CVE-2022-23451High· 8.1▾ TwilightBarbican authorization flaw before v14.0.0
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.2%
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
barbican < 14.0.0Upgrade to a patched release:
barbican 14.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-23452Medium· 4.9openstack-barbican Denial of Service vulnerability
CVE-2023-1636Medium· 6.0OpenStack Barbican information disclosure vulnerability
CVE-2023-1633Medium· 6.6OpenStack Barbican credential leak flaw