Barbican could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-5697-1 October 25, 2022 barbican vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Barbican could be made to expose sensitive information over the network. Software Description: - barbican: OpenStack Key Management Service - API Server Details: Douglas Mendizabal discovered that Barbican incorrectly handled certain query strings. A remote attacker could possibly use this issue to bypass the access policy. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: python3-barbican 2:14.0.0-0ubuntu1.1 Ubuntu 20.04 LTS: python3-barbican 1:10.1.0-0ubuntu2.2 Ubuntu 18.04 LTS: python-barbican 1:6.0.1-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: CVE-2022-3100 Package Information: https://launchpad.net/ubuntu/+source/barbican/2:14.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.2 https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.2 . A recent flaw in Barbican could lead to unauthorized access to confidential information. To safeguard your systems, ensure your Ubuntu installations are up to date.. Barbican Vulnerability, Access Policy Bypass, Ubuntu Security Notice. . LinuxSecurity.com Team
Douglas Mendizabal discovered that Barbican, the OpenStack Key Management Service, incorrectly parsed requests which could allow an authenticated user to bypass Barbican access policies. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5247-1
It was found that Barbican, a service for secret management and storage, was vulnerable to access bypass via query string injection. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3136-1
Several security issues were fixed in barbican.. =========================================================================Ubuntu Security Notice USN-5387-1 April 25, 2022 barbican vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in barbican. Software Description: - barbican: OpenStack Key Management Service - API Server Details: Douglas Mendizábal discovered that Barbican incorrectly handled access restrictions. An authenticated attacker could possibly use this issue to consume protected resources and possibly cause a denial of service. (CVE-2022-23451, CVE-2022-23452) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: python3-barbican 2:13.0.0-0ubuntu1.2 Ubuntu 20.04 LTS: python3-barbican 1:10.1.0-0ubuntu2.1 Ubuntu 18.04 LTS: python-barbican 1:6.0.1-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5387-1 CVE-2022-23451, CVE-2022-23452 Package Information: https://launchpad.net/ubuntu/+source/barbican/2:13.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.1 https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.1 . Multiple vulnerabilities were resolved in barbican for Ubuntu 21.10, 20.04 LTS, and 18.04 LTS. Ensure you update your system promptly.. Barbican Security, Ubuntu 21.10, Access Control, OpenStack Key Management. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.