CVE-2022-3100
published 2023-01-18CVE-2022-3100: A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
PriorityP334medium5.9CVSS 3.1
AVNACHPRLUINSUCHILAN
EPSS
0.43%
35.0th percentile
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | barbican | < barbican 1:15.0.0~rc3-1 (bookworm) | barbican 1:15.0.0~rc3-1 (bookworm) |
| openstack | barbican | >= 0 < 1:11.0.0-3+deb11u1 | 1:11.0.0-3+deb11u1 |
| openstack | barbican | >= 0 < 1:15.0.0~rc3-1 | 1:15.0.0~rc3-1 |
| openstack | barbican | >= 0 < 1:15.0.0~rc3-1 | 1:15.0.0~rc3-1 |
| openstack | barbican | >= 0 < 1:15.0.0~rc3-1 | 1:15.0.0~rc3-1 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack_for_ibm_power | — | — |
| redhat | openstack_for_ibm_power | — | — |
| redhat | openstack_for_ibm_power | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
osv5.9MEDIUM
vendor_cisco6.4MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Firewall 3100 Series Secure Boot Bypass Vulnerability
vendor_cisco·2022-11-09·CVSS 6.4
CVE-2022-20826 [MEDIUM] CWE-501 Cisco Secure Firewall 3100 Series Secure Boot Bypass Vulnerability
Cisco Secure Firewall 3100 Series Secure Boot Bypass Vulnerability
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality.
This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust.
Cisco has released software updates that address this vulnerability. There are n
Ubuntu
Barbican vulnerability
vendor_ubuntu·2022-10-25
CVE-2022-3100 Barbican vulnerability
Title: Barbican vulnerability
Summary: Barbican could be made to expose sensitive information over the
network.
Douglas Mendizabal discovered that Barbican incorrectly handled certain
query strings. A remote attacker could possibly use this issue to bypass
the access policy.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-barbican: access policy bypass via query string injection
vendor_redhat·2022-09-28·CVSS 5.9
CVE-2022-3100 [MEDIUM] CWE-305 openstack-barbican: access policy bypass via query string injection
openstack-barbican: access policy bypass via query string injection
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Debian
CVE-2022-3100: barbican - A flaw was found in the openstack-barbican component. This issue allows an acces...
vendor_debian·2022·CVSS 5.9
CVE-2022-3100 [MEDIUM] CVE-2022-3100: barbican - A flaw was found in the openstack-barbican component. This issue allows an acces...
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Scope: local
bookworm: resolved (fixed in 1:15.0.0~rc3-1)
bullseye: resolved (fixed in 1:11.0.0-3+deb11u1)
forky: resolved (fixed in 1:15.0.0~rc3-1)
sid: resolved (fixed in 1:15.0.0~rc3-1)
trixie: resolved (fixed in 1:15.0.0~rc3-1)
Cisco
Cisco Secure Firewall 3100 Series Secure Boot Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20826 Cisco Secure Firewall 3100 Series Secure Boot Bypass Vulnerability
CVE-2022-20826: Cisco Secure Firewall 3100 Series Secure Boot Bypass Vulnerability
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust. Cisco has released software updates that address this vulnerabilit
OSV
CVE-2022-3100: A flaw was found in the openstack-barbican component
osv·2023-01-18·CVSS 5.9
CVE-2022-3100 [MEDIUM] CVE-2022-3100: A flaw was found in the openstack-barbican component
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
GHSA
GHSA-5hg3-ffv7-g5ff: A flaw was found in the openstack-barbican component
ghsa_unreviewed·2023-01-18
CVE-2022-3100 [MEDIUM] CWE-305 GHSA-5hg3-ffv7-g5ff: A flaw was found in the openstack-barbican component
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-18
Published