CVE-2023-1636
published 2023-09-24CVE-2023-1636: A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration…
PriorityP428medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.48%
38.4th percentile
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | barbican | — | — |
| openstack | barbican | 0 – 16.0.0 | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Barbican information disclosure vulnerability
osv·2023-09-24
CVE-2023-1636 [MEDIUM] OpenStack Barbican information disclosure vulnerability
OpenStack Barbican information disclosure vulnerability
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
GHSA
OpenStack Barbican information disclosure vulnerability
ghsa·2023-09-24
CVE-2023-1636 [MEDIUM] OpenStack Barbican information disclosure vulnerability
OpenStack Barbican information disclosure vulnerability
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
Red Hat
openstack-barbican: incomplete container isolation
vendor_redhat·2023-04-21·CVSS 6.0
CVE-2023-1636 [MEDIUM] CWE-653 openstack-barbican: incomplete container isolation
openstack-barbican: incomplete container isolation
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
Pack
Debian
CVE-2023-1636: barbican - A vulnerability was found in OpenStack Barbican containers. This vulnerability i...
vendor_debian·2023·CVSS 6.0
CVE-2023-1636 [MEDIUM] CVE-2023-1636: barbican - A vulnerability was found in OpenStack Barbican containers. This vulnerability i...
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-24
Published