Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23451

Опубликовано: 13 дек. 2021
Источник: redhat
CVSS3: 7.1

Описание

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-barbicanOut of support scope
Red Hat OpenStack Platform 16.1openstack-barbicanFixedRHSA-2022:887407.12.2022
Red Hat OpenStack Platform 16.2openstack-barbicanFixedRHSA-2022:511422.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2025089openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 8.1
nvd
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 8.1
debian
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default pol ...

CVSS3: 8.1
github
больше 3 лет назад

Barbican authorization flaw before v14.0.0

7.1 High

CVSS3