-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.1.9 (openstack-barbican) security update Advisory ID: RHSA-2022:8874-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:8874 Issue date: 2022-12-07 CVE Names: CVE-2022-23451 CVE-2022-23452 ==================================================================== 1. Summary: An update for openstack-barbican is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 16.1 - noarch 3. Description: Barbican is a REST API designed for the secure storage, provisioning and management of secrets, including in OpenStack environments. Security Fix(es): * Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret (CVE-2022-23451) * Barbican allows anyone with an admin role to add their secrets to a different project's containers (CVE-2022-23452) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1965086 - barbican with atos HSM operations alternately succeed and fail 2025089 - CVE-2022-23451 openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret 2025090 - CVE-2022-23452 openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers 2025979 - Barbican unable to set up secrets 2026029 - Support of project owned keys 6. Package List: Red Hat OpenStack Platform 16.1: Source: openstack-barbican-9.0.1-1.20220916133702.07be198.el8ost.src.rpm noarch: openstack-barbican-9.0.1-1.20220916133702.07be198.el8ost.noarch.rpm openstack-barbican-api-9.0.1-1.20220916133702.07be198.el8ost.noarch.rpm openstack-barbican-common-9.0.1-1.20220916133702.07be198.el8ost.noarch.rpm openstack-barbican-keystone-listener-9.0.1-1.20220916133702.07be198.el8ost.noarch.rpm openstack-barbican-worker-9.0.1-1.20220916133702.07be198.el8ost.noarch.rpm python3-barbican-9.0.1-1.20220916133702.07be198.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-23451 https://access.redhat.com/security/cve/CVE-2022-23452 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY5FpgdzjgjWX9erEAQjT7Q//U9IyU9sgPQPj5R0N7E9R/aytkn0HrLKL 6pj6TvkuLciCCEEHzbq6L8RPC79Cg/wb7oEv0rH+qnCPyi7z1A1f8E1Ai3MOceDT gWCWnnEvkMZGuJQaT74vgLUdUFeMPc4HvAH098QjuZmuiEz8HSW69iXMWJM9cL7t zPzn9z0eK/zAiJZ+6QdQRe6nU/EI9X8wevbdFwakGJKfj7C7zAlcpz/6WOKTB+0D DfTpxkx+mgZprLym50rOGDw6uW3hwvatQwYYQxbs8fVzin6seKhB6A8GWBhT4VBh K2mPxNhA6mO8rFXviwhmKLpiECoLhmK9nwJ2yIicbgVv5EWJnlR7KkdnMywo9gO3 GJUdry29CvD7/XWqSvE8+9SxR3tcXPpSnCQvaLgH44eDPW9PZLZ0V6WCs6tfyddx LGLK9ozmkbjiX+FHSKMeEbpZFhJn45vc+79Navk9HBCu6kf++K5JC4XOGq9Mme3P kcvmBLF6M6dv3TOC2YuZF4ZSnBHVjpaObKf+4QXfRnNaPGP9G/0Z49e6D6lxZLg6 RUgwirZ6IG0F24CR6XZLhtjbohLvbTvSatYeWuDswSpuEzUnryN1TxfS1l2WM9Mx BZDzJOMnJdws9Nl72C+sxga3yc4aP0JDrnwgtbKArreiK+/4eJMk/cZOvOzkV47u GBk1JInQlDA=zYlG -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce