Description
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:LExploitability: 1.8 | Impact: 4.7Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: Low
Availability: Low
Affected Packages2 packages
🔴Vulnerability Details
3OSVOpenStack Barbican credential leak flaw↗2023-09-24 ▶ CVEListInsecure barbican configuration file leaking credential↗2023-09-24 ▶ GHSAOpenStack Barbican credential leak flaw↗2023-09-24 ▶ 📋Vendor Advisories
2Red Hatopenstack-barbican: Insecure Barbican configuration file leaking credential↗2023-04-21 ▶ DebianCVE-2023-1633: barbican - A credentials leak flaw was found in OpenStack Barbican. This flaw allows a loca...↗2023 ▶