cbcvebase.
CVE-2023-1636
published 2023-09-24

CVE-2023-1636: A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration…

PriorityP428medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.48%
38.4th percentile
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianbarbican
openstackbarbican0 – 16.0.0
redhatopenstack_platform
redhatopenstack_platform
redhatopenstack_platform

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.