Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23451

Опубликовано: 06 сент. 2022
Источник: debian

Описание

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
barbicanfixed1:14.0.0~rc1-2package
barbicanno-dsabullseyepackage
barbicanno-dsabusterpackage
barbicanno-dsastretchpackage

Примечания

  • https://storyboard.openstack.org/#!/story/2009253

  • https://bugzilla.redhat.com/show_bug.cgi?id=2025089

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 7.1
redhat
около 4 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 8.1
nvd
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 8.1
github
больше 3 лет назад

Barbican authorization flaw before v14.0.0