{"id":"CVE-2022-44020","aliases":["GHSA-5pj3-6fqm-8m7m","PYSEC-2026-1059"],"title":"OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions","summary":"OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","vendor":"sushy-tools","product":"sushy-tools","ecosystem":"pip","affected":["sushy-tools < 0.21.1","virtualbmc < 3.0.0"],"patched":["sushy-tools 0.21.1","virtualbmc 3.0.0"],"published":"2022-10-30","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-5pj3-6fqm-8m7m","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-44020"},{"url":"https://github.com/umago/virtualbmc"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GAD7QJIUWPCKJIGYP7PPHH5DILOEONFE"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEQVJF3OQGSDCSQTQQSC54JEGLMSNB4Q"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMSUGS4B6EBRHBJMTRXL5RIKJTZTEMJC"},{"url":"https://review.opendev.org/c/openstack/sushy-tools/+/862625"},{"url":"https://review.opendev.org/c/openstack/virtualbmc/+/862620"},{"url":"https://storyboard.openstack.org/#!/story/2010382"}],"tags":["osv","pip"],"epss":0.00228,"epssPercentile":0.1379,"ingestedAt":"2026-07-08T18:25:46.045Z","slug":"CVE-2022-44020","body":"## Overview\n\nAn issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an \"unsupported, production-like configuration.\"\n\n## Affected packages\n\n- `sushy-tools < 0.21.1`\n- `virtualbmc < 3.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `sushy-tools 0.21.1`\n- `virtualbmc 3.0.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}