CVE-2022-23451
Estado: ModificadaAlta (8.1)—
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.25%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-863
- CWE-863
Referencias
- https://access.redhat.com/security/cve/CVE-2022-23451
- https://bugzilla.redhat.com/show_bug.cgi?id=2022878
- https://bugzilla.redhat.com/show_bug.cgi?id=2025089
- https://review.opendev.org/c/openstack/barbican/+/811236
- https://storyboard.openstack.org/#%21/story/2009253
- https://access.redhat.com/security/cve/CVE-2022-23451
- https://bugzilla.redhat.com/show_bug.cgi?id=2022878
- https://bugzilla.redhat.com/show_bug.cgi?id=2025089
- https://review.opendev.org/c/openstack/barbican/+/811236
- https://storyboard.openstack.org/#%21/story/2009253
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-23451",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "openstack/barbican",
"versions": [
{
"status": "affected",
"version": "Fixed in v14.0.0"
}
]
}
]
}
],
"published": "2022-09-06T18:15:10.640",
"references": [
{
"url": "https://access.redhat.com/security/cve/CVE-2022-23451",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2022878",
"tags": [
"Issue Tracking",
"Permissions Required"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2025089",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://review.opendev.org/c/openstack/barbican/+/811236",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://storyboard.openstack.org/#%21/story/2009253",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2022-23451",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2022878",
"tags": [
"Issue Tracking",
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2025089",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://review.opendev.org/c/openstack/barbican/+/811236",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://storyboard.openstack.org/#%21/story/2009253",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources."
},
{
"lang": "es",
"value": "Se ha encontrado un fallo de autorización en openstack-barbican. Las reglas de política por defecto para la API de metadatos secretos permitían a cualquier usuario autenticado añadir, modificar o eliminar metadatos de cualquier secreto independientemente de su propiedad. Este fallo permite a un atacante en la red modificar o eliminar datos protegidos, causando una denegación de servicio al consumir recursos protegidos.\n"
}
],
"lastModified": "2026-06-17T04:30:08.933",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openstack:barbican:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0E48953-548A-4FDC-944E-A86EA5908E9A",
"versionEndExcluding": "14.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C52600BF-9E87-4CD2-91F3-685AFE478C1E"
},
{
"criteria": "cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCC81071-B46D-4F5D-AC25-B4A4CCC20C73"
},
{
"criteria": "cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B3000D2-35DF-4A93-9FC0-1AD3AB8349B8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}