A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2022-3100 | third party advisory |