CVE-2022-23452
published 2022-09-01CVE-2022-23452: An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an…
PriorityP421medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.02%
59.5th percentile
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | barbican | < barbican 1:14.0.0~rc1-2 (bookworm) | barbican 1:14.0.0~rc1-2 (bookworm) |
| openstack | barbican | < 14.0.0 | 14.0.0 |
| openstack | barbican | — | — |
| openstack | barbican | >= 0 < 1:14.0.0~rc1-2 | 1:14.0.0~rc1-2 |
| openstack | barbican | >= 0 < 1:14.0.0~rc1-2 | 1:14.0.0~rc1-2 |
| openstack | barbican | >= 0 < 1:14.0.0~rc1-2 | 1:14.0.0~rc1-2 |
| openstack | barbican | >= 0 < 14.0.0 | 14.0.0 |
| openstack | barbican | >= 0 < 1:6.0.1-0ubuntu1.1 | 1:6.0.1-0ubuntu1.1 |
| openstack | barbican | >= 0 < 1:10.1.0-0ubuntu2.1 | 1:10.1.0-0ubuntu2.1 |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Barbican vulnerabilities
vendor_ubuntu·2022-04-25·CVSS 8.1
CVE-2022-23452 [HIGH] Barbican vulnerabilities
Title: Barbican vulnerabilities
Summary: Several security issues were fixed in barbican.
Douglas Mendizábal discovered that Barbican incorrectly handled access
restrictions. An authenticated attacker could possibly use this issue to
consume protected resources and possibly cause a denial of service.
(CVE-2022-23451, CVE-2022-23452)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-23452: barbican - An authorization flaw was found in openstack-barbican, where anyone with an admi...
vendor_debian·2022·CVSS 4.9
CVE-2022-23452 [MEDIUM] CVE-2022-23452: barbican - An authorization flaw was found in openstack-barbican, where anyone with an admi...
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1:14.0.0~rc1-2)
bullseye: open
forky: resolved (fixed in 1:14.0.0~rc1-2)
sid: resolved (fixed in 1:14.0.0~rc1-2)
trixie: resolved (fixed in 1:14.0.0~rc1-2)
Red Hat
openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers
vendor_redhat·2021-12-13·CVSS 4.9
CVE-2022-23452 [MEDIUM] CWE-863 openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers
openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Package: openstack-barbican (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
GHSA
openstack-barbican Denial of Service vulnerability
ghsa·2022-09-02
CVE-2022-23452 [MEDIUM] CWE-863 openstack-barbican Denial of Service vulnerability
openstack-barbican Denial of Service vulnerability
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
OSV
openstack-barbican Denial of Service vulnerability
osv·2022-09-02
CVE-2022-23452 [MEDIUM] openstack-barbican Denial of Service vulnerability
openstack-barbican Denial of Service vulnerability
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
OSV
CVE-2022-23452: An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container
osv·2022-09-01·CVSS 4.9
CVE-2022-23452 [MEDIUM] CVE-2022-23452: An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
OSV
barbican vulnerabilities
osv·2022-04-25·CVSS 8.1
CVE-2022-23451 [HIGH] barbican vulnerabilities
barbican vulnerabilities
Douglas Mendizábal discovered that Barbican incorrectly handled access
restrictions. An authenticated attacker could possibly use this issue to
consume protected resources and possibly cause a denial of service.
(CVE-2022-23451, CVE-2022-23452)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-23452https://bugzilla.redhat.com/show_bug.cgi?id=2022908https://bugzilla.redhat.com/show_bug.cgi?id=2025090https://review.opendev.org/c/openstack/barbican/+/814200https://storyboard.openstack.org/#%21/story/2009297https://access.redhat.com/security/cve/CVE-2022-23452https://bugzilla.redhat.com/show_bug.cgi?id=2022908https://bugzilla.redhat.com/show_bug.cgi?id=2025090https://review.opendev.org/c/openstack/barbican/+/814200https://storyboard.openstack.org/#%21/story/2009297
2022-09-01
Published