Vulnerabilities > CVE-2022-3100 - Authentication Bypass by Primary Weakness vulnerability in multiple products

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
LOW
Availability impact
NONE
network
high complexity
openstack
redhat
CWE-305

Summary

A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.

Common Weakness Enumeration (CWE)