Vulnerabilities > CVE-2022-23451 - Incorrect Authorization vulnerability in multiple products

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
openstack
redhat
CWE-863

Summary

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

Vulnerable Configurations

Part Description Count
Application
Openstack
88
Application
Redhat
3

Common Weakness Enumeration (CWE)