CVE-2022-23452: Medium severity openstack barbican vulnerability
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Other sources
The default policy for adding a secret to a container allows anyone with the "admin" role to add a secret their project owns to a container that is owned by a different project.
References:
https://bugzilla.redhat.com/showbug.cgi?id=2022908
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-23452?
CVE-2022-23452 is an authorization flaw in openstack-barbican that allows anyone with an admin role to add secrets to a different project container, leading to potential resource consumption and denial of service.
How does CVE-2022-23452 impact OpenStack Barbican?
CVE-2022-23452 allows an attacker with admin role to add secrets to a different project container, enabling them to consume protected resources and cause denial of service.
What versions of OpenStack Barbican are affected by CVE-2022-23452?
OpenStack Barbican versions up to and excluding 14.0.0 are affected by CVE-2022-23452.
How can I mitigate the CVE-2022-23452 vulnerability?
To mitigate CVE-2022-23452, it is recommended to update OpenStack Barbican to a version higher than 14.0.0 or apply the necessary patches.
Where can I find more information about CVE-2022-23452?
You can find more information about CVE-2022-23452 in the following references: - [Red Hat Bugzilla - CVE-2022-23452](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2022908) - [OpenStack Storyboard - CVE-2022-23452](https://storyboard.openstack.org/#!/story/2009297) - [Red Hat Bugzilla - CVE-2022-23452 Patch](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2043278)