UbuntuUpdates.org

Package "barbican-api"

Name: barbican-api

Description:

OpenStack Key Management Service - API Server

Latest version: 1:6.0.1-0ubuntu1.2
Release: bionic (18.04)
Level: security
Repository: main
Head package: barbican
Homepage: https://github.com/openstack/barbican

Links


Download "barbican-api"


Other versions of "barbican-api" in Bionic

Repository Area Version
base main 1:6.0.0-0ubuntu1
updates main 1:6.0.1-0ubuntu1.2

Changelog

Version: 1:6.0.1-0ubuntu1.2 2022-10-25 13:06:20 UTC

  barbican (1:6.0.1-0ubuntu1.2) bionic-security; urgency=medium

  * SECURITY UPDATE: access policy bypass via query string injection
    - debian/patches/CVE-2022-3100.patch: don't use contents of query
      string in barbican/api/controllers/__init__.py.
    - CVE-2022-3100

 -- Marc Deslauriers <email address hidden> Wed, 05 Oct 2022 09:35:33 -0400

Source diff to previous version
CVE-2022-3100 access policy bypass via query string injection

Version: 1:6.0.1-0ubuntu1.1 2022-04-25 16:06:20 UTC

  barbican (1:6.0.1-0ubuntu1.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Access restrictions bypass
    - debian/patches/CVE-2022-23451.patch: Change access policies to
      secret metadata in barbican/common/policies/secretmeta.py. Add a new
      role in barbican/common/policies/base.py and make use of these changes
      in barbican/api/controllers/__init__.py,
      barbican/api/controllers/secretmeta.py and
      barbican/api/controllers/secrets.py.
    - debian/patches/CVE-2022-23451-post.patch: Change secret policies in
      barbican/common/policies/secrets.py, add tests in
      barbican/tests/api/test_resources_policy.py and
      functionaltests/api/v1/functional/test_secrets_rbac.py and update
      api guide in api-guide/source/acls.rst.
    - CVE-2022-23451
  * SECURITY UPDATE: Ownership bypass
    - debian/patches/CVE-2022-23452.patch: Update container secret policies
      in barbican/common/policies/containers.py and add a new role in
      barbican/common/policies/base.py.
    - CVE-2022-23452

 -- Rodrigo Figueiredo Zaiden <email address hidden> Thu, 21 Apr 2022 10:52:20 -0300




About   -   Send Feedback to @ubuntu_updates