RHSA-2022:5114MediumCVSS 7.1

Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 (openstack-barbican) security update

Published
June 22, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2022-23451 — openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret CVE-2022-23452 — openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers

🎯 Affected products8

  • Red Hat OpenStack Platform 16.2
  • openstack-barbican-0:9.0.2-2.20220122185348.c718783.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
  • openstack-barbican-0:9.0.2-2.20220122185348.c718783.el8ost.src as a component of Red Hat OpenStack Platform 16.2
  • openstack-barbican-api-0:9.0.2-2.20220122185348.c718783.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
  • openstack-barbican-common-0:9.0.2-2.20220122185348.c718783.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
  • openstack-barbican-keystone-listener-0:9.0.2-2.20220122185348.c718783.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
  • openstack-barbican-worker-0:9.0.2-2.20220122185348.c718783.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
  • python3-barbican-0:9.0.2-2.20220122185348.c718783.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (5)