VulnerabilityModified
CVE-2023-1636
A vulnerability was found in OpenStack Barbican containers.
MEDIUM 5.0EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
- CVSS 3.1
- 5.0 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-653
- Affected
- openstack/barbican · redhat/openstack platform
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2023-1636Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2181765Issue Tracking, Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-1636Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2181765Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.