Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-49299

Опубликовано: 28 мая 2026
Источник: debian
EPSS Низкий

Описание

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
neutronfixed2:28.0.0-4package
neutronfixed2:26.0.0-9+deb13u1trixiepackage
neutronno-dsabookwormpackage
neutronpostponedbullseyepackage

Примечания

  • https://security.openstack.org/ossa/OSSA-2026-016.html

EPSS

Процентиль: 21%
0.00295
Низкий

Связанные уязвимости

ubuntu
2 месяца назад

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

CVSS3: 4.3
redhat
2 месяца назад

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

nvd
2 месяца назад

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

github
2 месяца назад

OpenStack Neutron has an Incorrect Authorization issue

EPSS

Процентиль: 21%
0.00295
Низкий