PT-2022-15998 · Openstack+3 · Openstack-Barbican+3

Pedro Sampaio

·

Published

2022-01-28

·

Updated

2023-02-13

·

CVE-2022-23452

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions openstack-barbican (affected versions not specified)
Description An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-23452
GHSA-6P2H-RJJ7-2J63
RHSA-2022:5114
RHSA-2022:8874
SUSE-SU-2022:1729-1
USN-5387-1

Affected Products

Debian
Linuxmint
Ubuntu
Openstack-Barbican