Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. barbican
  4. ›
  5. CVE-2023-1636

CVE-2023-1636: OpenStack Barbican information disclosure vulnerability

September 24, 2023 (updated September 25, 2023)

A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.

References

  • access.redhat.com/security/cve/CVE-2023-1636
  • bugzilla.redhat.com/show_bug.cgi?id=2181765
  • github.com/advisories/GHSA-6rx9-c2rh-3qv4
  • nvd.nist.gov/vuln/detail/CVE-2023-1636

Code Behaviors & Features

Detect and mitigate CVE-2023-1636 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 16.0.0

Solution

Unfortunately, there is no solution available yet.

Impact 5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Learn more about CVSS

Source file

pypi/barbican/CVE-2023-1636.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:46 +0000.