CVE-2022-23451
published 2022-09-06CVE-2022-23451: An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or…
PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
1.01%
59.1th percentile
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | barbican | < barbican 1:14.0.0~rc1-2 (bookworm) | barbican 1:14.0.0~rc1-2 (bookworm) |
| openstack | barbican | < 14.0.0 | 14.0.0 |
| openstack | barbican | — | — |
| openstack | barbican | >= 0 < 1:14.0.0~rc1-2 | 1:14.0.0~rc1-2 |
| openstack | barbican | >= 0 < 1:14.0.0~rc1-2 | 1:14.0.0~rc1-2 |
| openstack | barbican | >= 0 < 1:14.0.0~rc1-2 | 1:14.0.0~rc1-2 |
| openstack | barbican | >= 0 < 14.0.0 | 14.0.0 |
| openstack | barbican | >= 0 < 1:6.0.1-0ubuntu1.1 | 1:6.0.1-0ubuntu1.1 |
| openstack | barbican | >= 0 < 1:10.1.0-0ubuntu2.1 | 1:10.1.0-0ubuntu2.1 |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Barbican authorization flaw before v14.0.0
osv·2022-09-07
CVE-2022-23451 [HIGH] Barbican authorization flaw before v14.0.0
Barbican authorization flaw before v14.0.0
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
GHSA
Barbican authorization flaw before v14.0.0
ghsa·2022-09-07
CVE-2022-23451 [HIGH] CWE-863 Barbican authorization flaw before v14.0.0
Barbican authorization flaw before v14.0.0
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
OSV
CVE-2022-23451: An authorization flaw was found in openstack-barbican
osv·2022-09-06·CVSS 8.1
CVE-2022-23451 [HIGH] CVE-2022-23451: An authorization flaw was found in openstack-barbican
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
OSV
barbican vulnerabilities
osv·2022-04-25·CVSS 8.1
CVE-2022-23451 [HIGH] barbican vulnerabilities
barbican vulnerabilities
Douglas Mendizábal discovered that Barbican incorrectly handled access
restrictions. An authenticated attacker could possibly use this issue to
consume protected resources and possibly cause a denial of service.
(CVE-2022-23451, CVE-2022-23452)
Ubuntu
Barbican vulnerabilities
vendor_ubuntu·2022-04-25·CVSS 8.1
CVE-2022-23452 [HIGH] Barbican vulnerabilities
Title: Barbican vulnerabilities
Summary: Several security issues were fixed in barbican.
Douglas Mendizábal discovered that Barbican incorrectly handled access
restrictions. An authenticated attacker could possibly use this issue to
consume protected resources and possibly cause a denial of service.
(CVE-2022-23451, CVE-2022-23452)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-23451: barbican - An authorization flaw was found in openstack-barbican. The default policy rules ...
vendor_debian·2022·CVSS 8.1
CVE-2022-23451 [HIGH] CVE-2022-23451: barbican - An authorization flaw was found in openstack-barbican. The default policy rules ...
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Scope: local
bookworm: resolved (fixed in 1:14.0.0~rc1-2)
bullseye: open
forky: resolved (fixed in 1:14.0.0~rc1-2)
sid: resolved (fixed in 1:14.0.0~rc1-2)
trixie: resolved (fixed in 1:14.0.0~rc1-2)
Red Hat
openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret
vendor_redhat·2021-12-13·CVSS 8.1
CVE-2022-23451 [HIGH] CWE-863 openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret
openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-23451https://bugzilla.redhat.com/show_bug.cgi?id=2022878https://bugzilla.redhat.com/show_bug.cgi?id=2025089https://review.opendev.org/c/openstack/barbican/+/811236https://storyboard.openstack.org/#%21/story/2009253https://access.redhat.com/security/cve/CVE-2022-23451https://bugzilla.redhat.com/show_bug.cgi?id=2022878https://bugzilla.redhat.com/show_bug.cgi?id=2025089https://review.opendev.org/c/openstack/barbican/+/811236https://storyboard.openstack.org/#%21/story/2009253
2022-09-06
Published