An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "35"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "36"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "37"
}
]
}
]
}{
"cpe": "cpe:2.3:a:opendev:sushy-tools:*:*:*:*:*:openstack:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.21.1"
}
]
}{
"cpe": "cpe:2.3:a:opendev:virtualbmc:*:*:*:*:*:openstack:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.0.0"
}
]
}