Debian Security Advisory
DSA-5247-1 barbican -- security update
- Date Reported:
- 04 Oct 2022
- Affected Packages:
- barbican
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 1021139.
In Mitre's CVE dictionary: CVE-2022-3100. - More information:
-
Douglas Mendizabal discovered that Barbican, the OpenStack Key Management Service, incorrectly parsed requests which could allow an authenticated user to bypass Barbican access policies.
For the stable distribution (bullseye), this problem has been fixed in version 1:11.0.0-3+deb11u1.
We recommend that you upgrade your barbican packages.
For the detailed security status of barbican please refer to its security tracker page at: https://security-tracker.debian.org/tracker/barbican