Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23452

Опубликовано: 01 сент. 2022
Источник: debian
EPSS Низкий

Описание

An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
barbicanfixed1:14.0.0~rc1-2package
barbicanno-dsabullseyepackage
barbicanno-dsabusterpackage
barbicanno-dsastretchpackage

Примечания

  • https://storyboard.openstack.org/#!/story/2009297

  • https://bugzilla.redhat.com/show_bug.cgi?id=2025090

EPSS

Процентиль: 59%
0.0038
Низкий

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 3 лет назад

An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

CVSS3: 3.8
redhat
около 4 лет назад

An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

CVSS3: 4.9
nvd
больше 3 лет назад

An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

CVSS3: 4.9
github
больше 3 лет назад

openstack-barbican Denial of Service vulnerability

EPSS

Процентиль: 59%
0.0038
Низкий