DSA-5247-1 barbican -- security update

Related Vulnerabilities: CVE-2022-3100  

Douglas Mendizabal discovered that Barbican, the OpenStack Key Management Service, incorrectly parsed requests which could allow an authenticated user to bypass Barbican access policies. For the stable distribution (bullseye), this problem has been fixed in version 1:11.0.0-3+deb11u1. We recommend that you upgrade your barbican packages. For the detailed security status of barbican please refer to its security tracker page at: https://security-tracker.debian.org/tracker/barbican

Debian Security Advisory

DSA-5247-1 barbican -- security update

Date Reported:
04 Oct 2022
Affected Packages:
barbican
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 1021139.
In Mitre's CVE dictionary: CVE-2022-3100.
More information:

Douglas Mendizabal discovered that Barbican, the OpenStack Key Management Service, incorrectly parsed requests which could allow an authenticated user to bypass Barbican access policies.

For the stable distribution (bullseye), this problem has been fixed in version 1:11.0.0-3+deb11u1.

We recommend that you upgrade your barbican packages.

For the detailed security status of barbican please refer to its security tracker page at: https://security-tracker.debian.org/tracker/barbican