UbuntuUpdates.org

Package "barbican-api"

Name: barbican-api

Description:

OpenStack Key Management Service - API Server

Latest version: 2:14.0.0-0ubuntu1.1
Release: jammy (22.04)
Level: security
Repository: main
Head package: barbican
Homepage: https://github.com/openstack/barbican

Links


Download "barbican-api"


Other versions of "barbican-api" in Jammy

Repository Area Version
base main 2:14.0.0-0ubuntu1
updates main 2:14.0.2-0ubuntu1

Changelog

Version: 2:14.0.0-0ubuntu1.1 2022-10-25 13:06:24 UTC

  barbican (2:14.0.0-0ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: access policy bypass via query string injection
    - debian/patches/CVE-2022-3100.patch: don't use contents of query
      string in barbican/api/controllers/__init__.py.
    - CVE-2022-3100

 -- Marc Deslauriers <email address hidden> Wed, 05 Oct 2022 09:29:42 -0400

CVE-2022-3100 access policy bypass via query string injection



About   -   Send Feedback to @ubuntu_updates