UbuntuUpdates.org

Package "barbican-common"

Name: barbican-common

Description:

OpenStack Key Management Service - common files

Latest version: 1:10.1.0-0ubuntu2.2
Release: focal (20.04)
Level: security
Repository: main
Head package: barbican
Homepage: https://github.com/openstack/barbican

Links


Download "barbican-common"


Other versions of "barbican-common" in Focal

Repository Area Version
base main 1:10.0.0~b2~git2020020508.7b14d983-0ubuntu3
updates main 1:10.1.0-0ubuntu2.2

Changelog

Version: 1:10.1.0-0ubuntu2.2 2022-10-25 13:06:23 UTC

  barbican (1:10.1.0-0ubuntu2.2) focal-security; urgency=medium

  * SECURITY UPDATE: access policy bypass via query string injection
    - debian/patches/CVE-2022-3100.patch: don't use contents of query
      string in barbican/api/controllers/__init__.py.
    - CVE-2022-3100

 -- Marc Deslauriers <email address hidden> Wed, 05 Oct 2022 09:31:21 -0400

Source diff to previous version
CVE-2022-3100 access policy bypass via query string injection

Version: 1:10.1.0-0ubuntu2.1 2022-04-25 16:06:23 UTC

  barbican (1:10.1.0-0ubuntu2.1) focal-security; urgency=medium

  * SECURITY UPDATE: Access restrictions bypass
    - debian/patches/CVE-2022-23451.patch: Change access policies to
      secret metadata in barbican/common/policies/secretmeta.py. Add a new
      role in barbican/common/policies/base.py and make use of these changes
      in barbican/api/controllers/__init__.py,
      barbican/api/controllers/secretmeta.py and
      barbican/api/controllers/secrets.py.
    - debian/patches/CVE-2022-23451-post.patch: Change secret policies in
      barbican/common/policies/secrets.py, add tests in
      barbican/tests/api/test_resources_policy.py and
      functionaltests/api/v1/functional/test_secrets_rbac.py and update
      api guide in api-guide/source/acls.rst.
    - CVE-2022-23451
  * SECURITY UPDATE: Ownership bypass
    - debian/patches/CVE-2022-23452.patch: Update container secret policies
      in barbican/common/policies/containers.py and add a new role in
      barbican/common/policies/base.py.
    - CVE-2022-23452

 -- Rodrigo Figueiredo Zaiden <email address hidden> Wed, 20 Apr 2022 18:00:29 -0300




About   -   Send Feedback to @ubuntu_updates