Vulnerability Description
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Barbican | - |
| Redhat | Openstack | 13 |
| Redhat | Openstack For Ibm Power | 13 |
| Redhat | Openstack Platform | 13.0 |
| Redhat | Enterprise Linux Eus | 7.6 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2022-3100Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-3100Third Party Advisory
FAQ
What is CVE-2022-3100?
CVE-2022-3100 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
How severe is CVE-2022-3100?
CVE-2022-3100 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3100?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Barbican, Redhat Openstack, Redhat Openstack For Ibm Power, Redhat Openstack Platform, Redhat Enterprise Linux Eus.