CVE-2023-1633
published 2023-09-24CVE-2023-1633: A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.19%
8.9th percentile
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | barbican | — | — |
| openstack | barbican | 0 – 16.0.0 | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_debian6.6LOW
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-barbican: Insecure Barbican configuration file leaking credential
vendor_redhat·2023-04-21·CVSS 6.6
CVE-2023-1633 [MEDIUM] CWE-200 openstack-barbican: Insecure Barbican configuration file leaking credential
openstack-barbican: Insecure Barbican configuration file leaking credential
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
Package: openstack-barbican (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Package: openstack-barbican (Red Hat OpenStack Platform 16.1) - Will not fix
Package: openstack-barbican (Red Hat OpenStack Platform 17.0) - Out of support scope
Debian
CVE-2023-1633: barbican - A credentials leak flaw was found in OpenStack Barbican. This flaw allows a loca...
vendor_debian·2023·CVSS 6.6
CVE-2023-1633 [MEDIUM] CVE-2023-1633: barbican - A credentials leak flaw was found in OpenStack Barbican. This flaw allows a loca...
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
OpenStack Barbican credential leak flaw
osv·2023-09-24
CVE-2023-1633 [MEDIUM] OpenStack Barbican credential leak flaw
OpenStack Barbican credential leak flaw
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
GHSA
OpenStack Barbican credential leak flaw
ghsa·2023-09-24
CVE-2023-1633 [MEDIUM] CWE-522 OpenStack Barbican credential leak flaw
OpenStack Barbican credential leak flaw
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-24
Published