openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret
Published Sep 6, 2022
8.1
HIGHCVSS 3.1
EPSS 1.25%
Description
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Affected products
- Vendor n/a Product Openstack/barbican Defaultunknown
Affected
- Fixed in v14.0.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Openstack/barbican | unknown | Affected
|
Configuration 2
- 13.0
- 16.1
- 16.2
No data.
Red Hat OpenStack Platform 16.1
openstack-barbican-0:9.0.1-1.20220916133702.07be198.el8ost
Fixed · RHSA-2022:8874
Red Hat OpenStack Platform 16.2
openstack-barbican-0:9.0.2-2.20220122185348.c718783.el8ost
Fixed · RHSA-2022:5114
Red Hat OpenStack Platform 13 (Queens)
openstack-barbican
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | openstack-barbican-0:9.0.1-1.20220916133702.07be198.el8ost | Fixed | RHSA-2022:8874 |
| Red Hat OpenStack Platform 16.2 | openstack-barbican-0:9.0.2-2.20220122185348.c718783.el8ost | Fixed | RHSA-2022:5114 |
| Red Hat OpenStack Platform 13 (Queens) | openstack-barbican | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/errata/RHSA-2022:5114
- https://access.redhat.com/errata/RHSA-2022:8874
- https://access.redhat.com/security/cve/CVE-2022-23451 x_refsource_MISCIssue TrackingThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2022878 x_refsource_MISCIssue TrackingPermissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=2025089 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6888 Advisory
- https://github.com/advisories/GHSA-p2jg-q8hw-p7gc Advisory
- https://github.com/openstack/barbican/commit/7d270bacbe29a90a10f1855abc3b50dac0f08022
- https://nvd.nist.gov/vuln/detail/CVE-2022-23451
- https://review.opendev.org/c/openstack/barbican/+/811236 x_refsource_MISCPatchThird Party Advisory
- https://storyboard.openstack.org/#%21/story/2009253 x_refsource_MISC
- https://www.cve.org/CVERecord?id=CVE-2022-23451
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2022:5114 | ||
| https://access.redhat.com/errata/RHSA-2022:8874 | ||
| https://access.redhat.com/security/cve/CVE-2022-23451 | x_refsource_MISCIssue TrackingThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2022878 | x_refsource_MISCIssue TrackingPermissions Required | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2025089 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6888 | Advisory | |
| https://github.com/advisories/GHSA-p2jg-q8hw-p7gc | Advisory | |
| https://github.com/openstack/barbican/commit/7d270bacbe29a90a10f1855abc3b50dac0f08022 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-23451 | ||
| https://review.opendev.org/c/openstack/barbican/+/811236 | x_refsource_MISCPatchThird Party Advisory | |
| https://storyboard.openstack.org/#%21/story/2009253 | x_refsource_MISC | |
| https://www.cve.org/CVERecord?id=CVE-2022-23451 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub