CVE-2022-23451
The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 1.24% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- openstack/barbican · redhat/openstack platform
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2022-23451Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2022878Issue Tracking, Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=2025089Issue Tracking, Third Party Advisory
- https://review.opendev.org/c/openstack/barbican/+/811236Patch, Third Party Advisory
- https://storyboard.openstack.org/#%21/story/2009253
- https://access.redhat.com/security/cve/CVE-2022-23451Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2022878Issue Tracking, Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=2025089Issue Tracking, Third Party Advisory
- https://review.opendev.org/c/openstack/barbican/+/811236Patch, Third Party Advisory
- https://storyboard.openstack.org/#%21/story/2009253
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.