<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:31:26.496721+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-13808</id>
    <title>EUVD-2026-13808</title>
    <updated>2026-10-02T19:31:26.502375+00:00</updated>
    <content>EUVD-2026-13808</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-13808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23451</id>
    <title>fkie_cve-2022-23451</title>
    <updated>2026-10-02T19:31:26.502409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p2jg-q8hw-p7gc</id>
    <title>GHSA-p2jg-q8hw-p7gc — Barbican authorization flaw before v14.0.0</title>
    <updated>2026-10-02T19:31:26.502441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: barbican</p>
<p>An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p2jg-q8hw-p7gc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23451</id>
    <title>gsd-2022-23451</title>
    <updated>2026-10-02T19:31:26.502465+00:00</updated>
    <content>gsd-2022-23451</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-786</id>
    <title>PYSEC-2026-786 — Barbican authorization flaw before v14.0.0</title>
    <updated>2026-10-02T19:31:26.502477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: barbican</p>
<p>An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5114</id>
    <title>RHSA-2022:5114 — Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 (openstack-barbican) security update</title>
    <updated>2026-10-02T19:31:26.502496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23451</id>
    <title>UBUNTU-CVE-2022-23451</title>
    <updated>2026-10-02T19:31:26.502516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: barbican, Ubuntu:18.04:LTS: barbican, Ubuntu:20.04:LTS: barbican</p>
<p>An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0439</id>
    <title>WID-SEC-W-2022-0439 — Red Hat OpenStack: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:31:26.502547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat OpenStack ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0439"/>
  </entry>
</feed>
