Lucene search

K
redhatRedHatRHSA-2022:8874
HistoryDec 07, 2022 - 8:09 p.m.

(RHSA-2022:8874) Moderate: Red Hat OpenStack Platform 16.1.9 (openstack-barbican) security update

2022-12-0720:09:58
access.redhat.com
17
red hat
openstack platform
barbican
security update
rest api
secrets management

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS

0.001

Percentile

50.3%

Barbican is a REST API designed for the secure storage, provisioning and
management of secrets, including in OpenStack environments.

Security Fix(es):

  • Barbican allows authenticated users to add/modify/delete arbitrary
    metadata on any secret (CVE-2022-23451)

  • Barbican allows anyone with an admin role to add their secrets to a
    different project’s containers (CVE-2022-23452)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS

0.001

Percentile

50.3%