5.9

CVE-2022-3100

A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenstackBarbican Version-
RedhatOpenstack Version13 SwEditionels
RedhatOpenstack Version16.1
RedhatOpenstack Version16.2 Update-
RedhatOpenstack Version17
RedhatOpenstack For Ibm Power Version13 SwEditionels
RedhatOpenstack Platform Version13.0
   RedhatEnterprise Linux Eus Version7.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.428
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 1.6 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.9 1.6 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
CWE-305 Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.