RHSA-2022:8874MediumCVSS 7.1

Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (openstack-barbican) security update

Published
December 7, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2022-23451 — openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret CVE-2022-23452 — openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers

🎯 Affected products8

  • Red Hat OpenStack Platform 16.1
  • openstack-barbican-0:9.0.1-1.20220916133702.07be198.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
  • openstack-barbican-0:9.0.1-1.20220916133702.07be198.el8ost.src as a component of Red Hat OpenStack Platform 16.1
  • openstack-barbican-api-0:9.0.1-1.20220916133702.07be198.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
  • openstack-barbican-common-0:9.0.1-1.20220916133702.07be198.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
  • openstack-barbican-keystone-listener-0:9.0.1-1.20220916133702.07be198.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
  • openstack-barbican-worker-0:9.0.1-1.20220916133702.07be198.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
  • python3-barbican-0:9.0.1-1.20220916133702.07be198.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (8)