CVE-2023-1633
EUVD-2023-244924.09.2023, 01:15
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openstack | barbican | - |
| redhat | openstack_platform | 16.1 |
| redhat | openstack_platform | 16.2 |
| redhat | openstack_platform | 17.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.