GHSA-p2jg-q8hw-p7gc · Severity: high · Ecosystem: pip — Barbican authorization flaw before v14.0.0
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Conclusion & alert: CVE-2022-23451 is rated Moderate Risk (52.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.97%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-17 | 0.93% | 0.97% | +0.04% |
| 2 | 2026-06-15 | 0.34% | 0.93% | +0.59% |
| 3 | 2026-04-14 | — | 0.34% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.8 | 5.2 | [email protected] |
GHSA-p2jg-q8hw-p7gc · Severity: high · Ecosystem: pip — Barbican authorization flaw before v14.0.0
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-23451 not yet assigned priority: Debian including 1 source packages (barbican), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2022-23451 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2022-23451 |
suse
|
medium | CVE-2022-23451 severity moderate: SUSE including 59 source package names (ardana-barbican-9.0+git.1644879908.8a641c1-3.13.1, grafana-6.7.4-3.26.1, …), 99 product×package rows across 2 product lines (SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 9): Fixed 99. | https://www.suse.com/security/cve/CVE-2022-23451/ |
ubuntu
|
medium | CVE-2022-23451 medium priority: Ubuntu including 1 source packages (barbican), 14 status rows across 14 suites (bionic, focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 8, released 4, ignored 1, needed 1. | https://ubuntu.com/security/CVE-2022-23451 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openstack | barbican | < 14.0.0 | cpe:2.3:a:openstack:barbican:*:*:*:*:*:*:*:* |
| redhat | openstack_platform | 13.0 | cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:* |
| redhat | openstack_platform | 16.1 | cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:* |
| redhat | openstack_platform | 16.2 | cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2022-23451 | Issue Tracking Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2022878 | Issue Tracking Permissions Required |
| https://bugzilla.redhat.com/show_bug.cgi?id=2025089 | Issue Tracking Third Party Advisory |
| https://review.opendev.org/c/openstack/barbican/+/811236 | Patch Third Party Advisory |
| https://storyboard.openstack.org/#%21/story/2009253 |