Search CVE reports
1 – 5 of 5 results
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the...
1 affected package
barbican
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
barbican | — | Not affected | Not affected | Not affected |
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
1 affected package
barbican
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
barbican | — | Not affected | Not affected | Not affected |
Some fixes available 3 of 4
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
1 affected package
barbican
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
barbican | Not affected | Fixed | Fixed | Fixed |
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a...
1 affected package
barbican
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
barbican | — | Not affected | Fixed | Fixed |
Some fixes available 3 of 4
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw...
1 affected package
barbican
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
barbican | Not affected | Not affected | Fixed | Fixed |