barbican@20.0.0.0rc1 vulnerabilities

Service for storing sensitive client information for OpenStack

Direct Vulnerabilities

Known vulnerabilities in the barbican package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Isolation or Compartmentalization

barbican is an OpenStack Secure Key Management

Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization. Barbican containers share the same CGROUP, USER and NET namespace with the host system and other OpenStack services. If any service is compromised it could gain access the data transmitted to and from Barbican.

Note This vulnerability is only applicable to deployments which utilize an all-in-one configuration.

How to fix Improper Isolation or Compartmentalization?

There is no fixed version for barbican.

[0,)
  • M
Information Exposure

barbican is an OpenStack Secure Key Management

Affected versions of this package are vulnerable to Information Exposure. A local authenticated attacker may be able to read the configuration file, gaining access to sensitive credentials.

How to fix Information Exposure?

There is no fixed version for barbican.

[0,)