Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3277

Опубликовано: 06 мар. 2023
Источник: debian
EPSS Низкий

Описание

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
neutronfixed2:21.0.0~rc1-3package
neutronno-dsabullseyepackage
neutronno-dsabusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2129193

  • When fixing this issue this might open CVE-2023-3637 if fixed incompletely.

  • https://review.opendev.org/q/Ieef7011f48cd2188d4254ff16d90a6465bbabfe3

  • https://opendev.org/openstack/neutron/commit/01fc2b9195f999df4d810df4ee63f77ecbc81f7e

EPSS

Процентиль: 64%
0.0047
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 4.3
redhat
больше 3 лет назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
nvd
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
github
почти 3 года назад

openstack-neutron uncontrolled resource consumption flaw

EPSS

Процентиль: 64%
0.0047
Низкий