CVE-2023-1633: Insecure barbican configuration file leaking credential
A barbican configuration file is set to world-readable in Red Hat OpenStack. This presents a security risk as it allows authenticated attacker with limited access to the file to view its contents, including secure credential.
Other sources
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1633?
CVE-2023-1633 is a credentials leak flaw found in OpenStack Barbican, which allows a local authenticated attacker to read the configuration file and gain access to sensitive credentials.
How does CVE-2023-1633 affect OpenStack Barbican?
CVE-2023-1633 affects OpenStack Barbican by allowing a local authenticated attacker to read the configuration file and gain access to sensitive credentials.
What is the severity of CVE-2023-1633?
CVE-2023-1633 has a severity rating of medium with a CVSS score of 6.6.
Which versions of OpenStack Barbican are affected by CVE-2023-1633?
Versions up to and including 16.0.0 of OpenStack Barbican are affected by CVE-2023-1633.
How can I fix CVE-2023-1633?
To fix CVE-2023-1633, update to a version of OpenStack Barbican that is not affected by the vulnerability.