Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-1636
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incomplete container isolation
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
不充分的划分
Source: NVD (National Vulnerability Database)
Vulnerability Title
barbican 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
barbican是 OpenStack 密钥管理服务,API 服务器。 barbican存在安全漏洞,该漏洞源于在 Red Hat OpenStack 中存在容器隔离缺陷,允许攻击者对 Barbican 容器进行有限的身份验证和访问,从而有可能访问其他 OpenStack 容器和服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-openstack-barbican--
Red HatRed Hat OpenStack Platform 13 (Queens)-cpe:/a:redhat:openstack:13
Red HatRed Hat OpenStack Platform 16.1-cpe:/a:redhat:openstack:16.1
Red HatRed Hat OpenStack Platform 16.2-cpe:/a:redhat:openstack:16.2
Red HatRed Hat OpenStack Platform 17.0-cpe:/a:redhat:openstack:17.0
RDOOpenStack RDO--
II. Public POCs for CVE-2023-1636
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-1636
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2023-1636

No comments yet


Leave a comment