A barbican configuration file is set to world-readable in Red Hat OpenStack. This presents a security risk as it allows authenticated attacker with limited access to the file to view its contents, including secure credential.
Created openstack-barbican tracking bugs for this issue: Affects: openstack-rdo [bug 2188734]
Hi, (In reply to Nick Tait from comment #0) > A barbican configuration file is set to world-readable in Red Hat OpenStack. > This presents a security risk as it allows authenticated attacker with > limited access to the file to view its contents, including secure credential. I'm trying to triage this CVE (CVE-2023-1633) for a downstream distribution but this bugzilla entry was the only cross-reference available. Can you share more on the CVE, does it affect upstream barbican and was it reported there? Can you provide more information on it? Regards, Salvatore
Yes, sorry for the sparse content at this stage. This is very likely the first public reference to this issue (along with CVE-2023-1636). Both issues came via the same reporter. I believe they both only affect downstream RHOSP. I'm following up with the reporter to get more details. (Will not clear the needinfos as a reminder to myself)
Hi Nick, (In reply to Nick Tait from comment #5) > Yes, sorry for the sparse content at this stage. This is very likely the > first public reference to this issue (along with CVE-2023-1636). Both issues > came via the same reporter. I believe they both only affect downstream > RHOSP. I'm following up with the reporter to get more details. (Will not > clear the needinfos as a reminder to myself) I see the needinfo was canclelled, did you got more information on this (and as you correctly pointed out CVE-2023-1636) issues? Thank you already! Regards, Salvatore
Still waiting on reporter, but I did send them a reminder. Feel free to send me another needinfo in a few days...
Hi Nick, (In reply to Nick Tait from comment #9) > Still waiting on reporter, but I did send them a reminder. Feel free to send > me another needinfo in a few days... Any news on this and on the other barbican issue?
Thanks for following up, unfortunately I never received any additional details.
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2023:6231 https://access.redhat.com/errata/RHSA-2023:6231