5.9

CVE-2022-3100

A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openstack ≫ Barbican Version -
Redhat ≫ Openstack Version 13 SwEdition els
Redhat ≫ Openstack Version 16.1
Redhat ≫ Openstack Version 16.2 Update -
Redhat ≫ Openstack Version 17
Redhat ≫ Openstack For Ibm Power Version 13 SwEdition els
Redhat ≫ Openstack For Ibm Power Version 16.1
Redhat ≫ Openstack For Ibm Power Version 16.2
Redhat ≫ Openstack Platform Version 13.0
   Redhat ≫ Enterprise Linux Eus Version 7.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.344
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 1.6 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
CISA-ADP 5.9 1.6 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
CWE-305 Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

https://access.redhat.com/security/cve/CVE-2022-3100
Third Party Advisory