Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-23451

Опубликовано: 06 сент. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

РелизСтатусПримечание
bionic

released

1:6.0.1-0ubuntu1.1
devel

not-affected

2:14.0.0-0ubuntu1
esm-apps/xenial

needed

esm-infra/bionic

released

1:6.0.1-0ubuntu1.1
esm-infra/focal

released

1:10.1.0-0ubuntu2.1
focal

released

1:10.1.0-0ubuntu2.1
impish

released

2:13.0.0-0ubuntu1.2
jammy

not-affected

2:14.0.0-0ubuntu1
kinetic

not-affected

2:14.0.0-0ubuntu1
lunar

not-affected

2:14.0.0-0ubuntu1

Показывать по

EPSS

Процентиль: 63%
0.00437
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
около 4 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 8.1
nvd
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

CVSS3: 8.1
debian
больше 3 лет назад

An authorization flaw was found in openstack-barbican. The default pol ...

CVSS3: 8.1
github
больше 3 лет назад

Barbican authorization flaw before v14.0.0

EPSS

Процентиль: 63%
0.00437
Низкий

8.1 High

CVSS3