USN-5697-1: Barbican vulnerability
25 October 2022
Barbican could be made to expose sensitive information over the network.
Releases
Packages
- barbican - OpenStack Key Management Service - API Server
Details
Douglas Mendizabal discovered that Barbican incorrectly handled certain
query strings. A remote attacker could possibly use this issue to bypass
the access policy.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
In general, a standard system update will make all the necessary changes.