Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w446-h7vg-wv3p

Опубликовано: 07 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

openstack-neutron uncontrolled resource consumption flaw

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Пакеты

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 19.0.0.0rc1, < 19.5.0

19.5.0

Наименование

neutron

pip
Затронутые версииВерсия исправления

< 18.6.0

18.6.0

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 20.0.0.0rc1, < 20.3.0

20.3.0

EPSS

Процентиль: 64%
0.0047
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 4.3
redhat
больше 3 лет назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
nvd
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
debian
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutr ...

EPSS

Процентиль: 64%
0.0047
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400