VendorsOpenStackbarbicanall versions
Vulnerabilities

OpenStack Barbican

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-23451
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Published 2022-09-06 · Modified
8.1EPSS 0.013
CVE-2023-1633
Insecure barbican configuration file leaking credential
Published 2023-09-24 · Modified
6.6EPSS 0.002
CVE-2023-1636
Incomplete container isolation
Published 2023-09-24 · Modified
6.0EPSS 0.005
CVE-2022-3100
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Published 2023-01-18 · Modified
5.9EPSS 0.004
CVE-2022-23452
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Published 2022-09-01 · Modified
4.9EPSS 0.013