Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown
CVE-2023-1636
Disclosure Date: September 24, 2023 (last updated October 08, 2023)
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
0
Attacker Value
Unknown
CVE-2023-1633
Disclosure Date: September 24, 2023 (last updated October 08, 2023)
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
0
Attacker Value
Unknown
CVE-2023-1625
Disclosure Date: September 24, 2023 (last updated October 08, 2023)
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
0
Attacker Value
Unknown
CVE-2023-1668
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
0
Attacker Value
Unknown
CVE-2022-3277
Disclosure Date: March 06, 2023 (last updated October 08, 2023)
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
0
Attacker Value
Unknown
CVE-2022-3100
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
0
Attacker Value
Unknown
CVE-2022-23451
Disclosure Date: September 06, 2022 (last updated October 08, 2023)
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
0
Attacker Value
Unknown
CVE-2022-2447
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
0
Attacker Value
Unknown
CVE-2022-23452
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
0
Attacker Value
Unknown
CVE-2022-0718
Disclosure Date: August 29, 2022 (last updated October 08, 2023)
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
0