Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 22.04 LTS: USN-5697-1 High: Barbican Data Exposure Risk

Barbican could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-5697-1 October 25, 2022 barbican vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Barbican could be made to expose sensitive information over the network. Software Description: - barbican: OpenStack Key Management Service - API Server Details: Douglas Mendizabal discovered that Barbican incorrectly handled certain query strings. A remote attacker could possibly use this issue to bypass the access policy. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: python3-barbican 2:14.0.0-0ubuntu1.1 Ubuntu 20.04 LTS: python3-barbican 1:10.1.0-0ubuntu2.2 Ubuntu 18.04 LTS: python-barbican 1:6.0.1-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: CVE-2022-3100 Package Information: https://launchpad.net/ubuntu/+source/barbican/2:14.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.2 https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.2 . A recent flaw in Barbican could lead to unauthorized access to confidential information. To safeguard your systems, ensure your Ubuntu installations are up to date.. Barbican Vulnerability, Access Policy Bypass, Ubuntu Security Notice. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2022 Ubuntu
87

Debian: DSA-5283-1 Important: KeyManager Access Control Flaw

Douglas Mendizabal discovered that Barbican, the OpenStack Key Management Service, incorrectly parsed requests which could allow an authenticated user to bypass Barbican access policies. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5247-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 04, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : barbican CVE ID : CVE-2022-3100 Debian Bug : 1021139 Douglas Mendizabal discovered that Barbican, the OpenStack Key Management Service, incorrectly parsed requests which could allow an authenticated user to bypass Barbican access policies. For the stable distribution (bullseye), this problem has been fixed in version 1:11.0.0-3+deb11u1. We recommend that you upgrade your barbican packages. For the detailed security status of barbican please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/barbican Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Barbican update for Debian fixes a critical vulnerability in request handling that might allow access control circumvention. Users should upgrade immediately. Barbican Update, Debian Security, Access Control Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 04, 2022 Important Debian
197

Debian 10 Buster DLA-3136-1 Critical: Barbican Access Bypass

It was found that Barbican, a service for secret management and storage, was vulnerable to access bypass via query string injection. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3136-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort October 04, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : barbican Version : 1:7.0.0-1+deb10u1 CVE ID : CVE-2022-3100 It was found that Barbican, a service for secret management and storage, was vulnerable to access bypass via query string injection. For Debian 10 buster, this problem has been fixed in version 1:7.0.0-1+deb10u1. We recommend that you upgrade your barbican packages. For the detailed security status of barbican please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/barbican Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4890-1 resolves a severe code execution vulnerability in Nova due to improper input validation. Update immediately.. secretManagement, accessBypass, debianUpdate, barbicanSecurity, queryInjection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 04, 2022 Critical Debian LTS
172

Ubuntu 21.10: USN-5387-1 Critical Access Restriction in Barbican

Several security issues were fixed in barbican.. =========================================================================Ubuntu Security Notice USN-5387-1 April 25, 2022 barbican vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in barbican. Software Description: - barbican: OpenStack Key Management Service - API Server Details: Douglas Mendizábal discovered that Barbican incorrectly handled access restrictions. An authenticated attacker could possibly use this issue to consume protected resources and possibly cause a denial of service. (CVE-2022-23451, CVE-2022-23452) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: python3-barbican 2:13.0.0-0ubuntu1.2 Ubuntu 20.04 LTS: python3-barbican 1:10.1.0-0ubuntu2.1 Ubuntu 18.04 LTS: python-barbican 1:6.0.1-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5387-1 CVE-2022-23451, CVE-2022-23452 Package Information: https://launchpad.net/ubuntu/+source/barbican/2:13.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.1 https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.1 . Multiple vulnerabilities were resolved in barbican for Ubuntu 21.10, 20.04 LTS, and 18.04 LTS. Ensure you update your system promptly.. Barbican Security, Ubuntu 21.10, Access Control, OpenStack Key Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 25, 2022 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here