CVE-2023-1633

MEDIUM

OpenStack Barbican - Info Disclosure

Title source: llm

Description

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.

Scores

CVSS v3 6.6
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Classification

CWE
CWE-522 CWE-200
Status published

Affected Products (5)

openstack/barbican
redhat/openstack_platform
redhat/openstack_platform
redhat/openstack_platform
pypi/barbican PyPI

Timeline

Published Sep 24, 2023
Tracked Since Feb 18, 2026