CVE-2022-23451: High severity openstack barbican vulnerability
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Other sources
The default policy rules for the secret metadata API allow any authenticated user to add, modify, or delete metadata from any secret regardless of ownership.
References:
https://bugzilla.redhat.com/showbug.cgi?id=2022878
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-23451.
What is the title of this vulnerability?
The title of this vulnerability is 'An authorization flaw was found in openstack-barbican'.
What is the severity of CVE-2022-23451?
The severity of CVE-2022-23451 is high with a severity value of 8.1.
Which software is affected by CVE-2022-23451?
OpenStack Barbican, Redhat Openstack Platform versions 13.0, 16.1, and 16.2 are affected by CVE-2022-23451.
How can an attacker exploit CVE-2022-23451?
An attacker on the network can exploit CVE-2022-23451 to modify or delete protected data by using the default policy rules for the secret metadata API.