CVE-2023-1636
Published Sep 24, 2023A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers shar…
Vendor/product archive
5 CVEs tagged to openstack / barbican — 0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers shar…
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from…
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the netw…