barbican 1:6.0.1-0ubuntu1.1 source package in Ubuntu

Changelog

barbican (1:6.0.1-0ubuntu1.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Access restrictions bypass
    - debian/patches/CVE-2022-23451.patch: Change access policies to
      secret metadata in barbican/common/policies/secretmeta.py. Add a new
      role in barbican/common/policies/base.py and make use of these changes
      in barbican/api/controllers/__init__.py,
      barbican/api/controllers/secretmeta.py and
      barbican/api/controllers/secrets.py.
    - debian/patches/CVE-2022-23451-post.patch: Change secret policies in
      barbican/common/policies/secrets.py, add tests in
      barbican/tests/api/test_resources_policy.py and
      functionaltests/api/v1/functional/test_secrets_rbac.py and update
      api guide in api-guide/source/acls.rst.
    - CVE-2022-23451
  * SECURITY UPDATE: Ownership bypass
    - debian/patches/CVE-2022-23452.patch: Update container secret policies
      in barbican/common/policies/containers.py and add a new role in
      barbican/common/policies/base.py.
    - CVE-2022-23452

 -- Rodrigo Figueiredo Zaiden <email address hidden>  Thu, 21 Apr 2022 10:52:20 -0300

Upload details

Uploaded by:
Rodrigo Figueiredo Zaiden
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Bionic: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
barbican_6.0.1.orig.tar.gz 593.9 KiB 4e2f6a88fe60adf810fb70c899303553c64eadd04c50e2d7bc5cc2e65395470d
barbican_6.0.1-0ubuntu1.1.debian.tar.xz 13.1 KiB 0dbd7918e6e03c1c33446aa1d6c391f20cbecde5d3421554965c22b39ddcadbf
barbican_6.0.1-0ubuntu1.1.dsc 3.5 KiB b2738ecf7eed62c6292ac85e8e54211b7bc7822fff31a6f72d721be747ca1979

View changes file

Binary packages built by this source

barbican-api: OpenStack Key Management Service - API Server

 The Barbican project provides services for secure storage, provisioning and
 management of sensitive client secret information such as encryption keys. It
 is aims at being useful for all environments, including large ephemeral
 Clouds.
 .
 This package contains the Barbican API Server.

barbican-common: OpenStack Key Management Service - common files

 The Barbican project provides services for secure storage, provisioning and
 management of sensitive client secret information such as encryption keys. It
 is aims at being useful for all environments, including large ephemeral
 Clouds.
 .
 This package contains common files for Barbican.

barbican-doc: OpenStack Key Management Service - doc

 The Barbican project provides services for secure storage, provisioning and
 management of sensitive client secret information such as encryption keys. It
 is aims at being useful for all environments, including large ephemeral
 Clouds.
 .
 This package contains the documentation.

barbican-keystone-listener: OpenStack Key Management Service - Keystone Listener

 The Barbican project provides services for secure storage, provisioning and
 management of sensitive client secret information such as encryption keys. It
 is aims at being useful for all environments, including large ephemeral
 Clouds.
 .
 This package contains the Barbican Keystone Listener daemon.

barbican-worker: OpenStack Key Management Service - Worker Node

 The Barbican project provides services for secure storage, provisioning and
 management of sensitive client secret information such as encryption keys. It
 is aims at being useful for all environments, including large ephemeral
 Clouds.
 .
 This package contains the Barbican Worker Node.

python-barbican: OpenStack Key Management Service - Python files

 The Barbican project provides services for secure storage, provisioning and
 management of sensitive client secret information such as encryption keys. It
 is aims at being useful for all environments, including large ephemeral
 Clouds.
 .
 This package contains the Python files and libraries.