A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
{ "urgency": "not yet assigned" }