Rapid7 Vulnerability & Exploit Database

Ubuntu: USN-5387-1 (CVE-2022-23451): Barbican vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Ubuntu: USN-5387-1 (CVE-2022-23451): Barbican vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
04/25/2022
Created
04/28/2022
Added
04/26/2022
Modified
03/22/2023

Description

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

Solution(s)

  • ubuntu-upgrade-python-barbican
  • ubuntu-upgrade-python3-barbican

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;