The default policy rules for the secret metadata API allow any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. References: https://bugzilla.redhat.com/show_bug.cgi?id=2022878
Upstream issue: https://storyboard.openstack.org/#!/story/2009253
Created openstack-barbican tracking bugs for this issue: Affects: openstack-rdo [bug 2043274]
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2022:5114 https://access.redhat.com/errata/RHSA-2022:5114
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-23451
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2022:8874 https://access.redhat.com/errata/RHSA-2022:8874