Description
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6721 | An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. |
Github GHSA |
GHSA-6p2h-rjj7-2j63 | openstack-barbican Denial of Service vulnerability |
Ubuntu USN |
USN-5387-1 | Barbican vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T03:43:45.996Z
Reserved: 2022-01-19T00:00:00.000Z
Link: CVE-2022-23452
No data.
Status : Modified
Published: 2022-09-01T21:15:09.173
Modified: 2024-11-21T06:48:35.107
Link: CVE-2022-23452
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN