Bug 2138201 - virtualbmc: credential leak
Summary: virtualbmc: credential leak
Keywords:
Status: NEW
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2138219
Blocks: 2138198
TreeView+ depends on / blocked
 
Reported: 2022-10-27 14:55 UTC by Sage McTaggart
Modified: 2023-07-07 08:31 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sage McTaggart 2022-10-27 14:55:16 UTC
A vulnerability was discovered in virutalbmc impacting rhosp 13. If a user configured a VNC console for a virtual machine under virtualbmc's power/boot device management, the password could be stripped from the libvirt virtual machine domain.

* Upstream Storyboard: https://storyboard.openstack.org/#!/story/2010382
* Downstream BZ: https://bugzilla.redhat.com/show_bug.cgi?id=2137679
* Impacted package:
https://brewweb.engineering.redhat.com/brew/packageinfo?packageID=61530
* Impacted RPM for RHOSP13
https://brewweb.engineering.redhat.com/brew/buildinfo?buildID=666478

Comment 2 Sage McTaggart 2022-11-11 16:01:35 UTC
Lifting eternal embargo and closing as duplicate of  https://bugzilla.redhat.com/show_bug.cgi?id=2137679  which has been public from the start


Note You need to log in before you can comment on or make changes to this bug.