CVE-2022-23451
Summary
| CVE | CVE-2022-23451 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-06 18:15:00 UTC |
| Updated | 2023-02-12 22:15:00 UTC |
| Description | An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182801 Debian Security Update for barbican (CVE-2022-23451)
- 198750 Ubuntu Security Notification for Barbican Vulnerabilities (USN-5387-1)
- 240486 Red Hat Update for OpenStack Platform 16.2 (RHSA-2022:5114)
- 240985 Red Hat Update for OpenStack Platform 16.1.9 (RHSA-2022:8874)