Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f27h-g923-68hw

Опубликовано: 25 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.5

Описание

OpenStack Neutron can use an incorrect ID during policy enforcement

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

Пакеты

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 23.0.0, < 23.2.1

23.2.1

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 24.0.0, < 24.0.2

24.0.2

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 25.0.0, < 25.0.1

25.0.1

EPSS

Процентиль: 49%
0.00257
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-345
CWE-754

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

CVSS3: 5.3
redhat
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

CVSS3: 7.5
nvd
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

CVSS3: 7.5
debian
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can ...

EPSS

Процентиль: 49%
0.00257
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-345
CWE-754