=========================================================================Ubuntu Security Notice USN-5697-1
October 25, 2022

barbican vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Barbican could be made to expose sensitive information over the
network.

Software Description:
- barbican: OpenStack Key Management Service - API Server

Details:

Douglas Mendizabal discovered that Barbican incorrectly handled certain
query strings. A remote attacker could possibly use this issue to bypass
the access policy.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
   python3-barbican                2:14.0.0-0ubuntu1.1

Ubuntu 20.04 LTS:
   python3-barbican                1:10.1.0-0ubuntu2.2

Ubuntu 18.04 LTS:
   python-barbican                 1:6.0.1-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5697-1
   CVE-2022-3100

Package Information:
   https://launchpad.net/ubuntu/+source/barbican/2:14.0.0-0ubuntu1.1
   https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.2
   https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.2

Ubuntu 5697-1: Barbican vulnerability

October 25, 2022
Barbican could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: python3-barbican 2:14.0.0-0ubuntu1.1 Ubuntu 20.04 LTS: python3-barbican 1:10.1.0-0ubuntu2.2 Ubuntu 18.04 LTS: python-barbican 1:6.0.1-0ubuntu1.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5697-1

CVE-2022-3100

Severity
October 25, 2022

Package Information

https://launchpad.net/ubuntu/+source/barbican/2:14.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.2 https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.2

Related News