Back to search
CVE-2022-23452
Published: Sep 1, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
| Vendor | Product | Versions |
|---|---|---|
n/a | openstack/barbican | affected Fixed in v14.0.0 |
Weaknesses (CWE)
References
https://bugzilla.redhat.com/show_bug.cgi?id=2025090
x_refsource_MISC
https://bugzilla.redhat.com/show_bug.cgi?id=2022908
x_refsource_MISC
https://storyboard.openstack.org/#%21/story/2009297
x_refsource_MISC
https://review.opendev.org/c/openstack/barbican/+/814200
x_refsource_MISC
https://access.redhat.com/security/cve/CVE-2022-23452
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now