CVE-2023-1633
24.09.2023, 01:15
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | barbican | - |
redhat | openstack_platform | 16.1 |
redhat | openstack_platform | 16.2 |
redhat | openstack_platform | 17.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.