Back

HIGH

openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret

Published Sep 6, 2022

Description

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

Affected products

Remediation

No remediation recorded yet.

References (12)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 6, 2022
Updated Aug 3, 2024
Reserved Jan 19, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Dec 13, 2021
Bugzilla 2025089

ENISA EUVD

Assigner redhat
Published Sep 6, 2022
Updated Aug 3, 2024