Lucene search

K
cvelistRedhatCVELIST:CVE-2022-23452
HistorySep 01, 2022 - 8:57 p.m.

CVE-2022-23452

2022-09-0120:57:45
CWE-863
redhat
www.cve.org
6
openstack barbican
authorization flaw
admin role
secrets
different project
denial of service

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

50.3%

An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

CNA Affected

[
  {
    "product": "openstack/barbican",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in v14.0.0"
      }
    ]
  }
]

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

50.3%