Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3277

Опубликовано: 06 мар. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*
Версия до 18.6.0 (исключая)
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*
Версия от 19.0.0 (включая) до 19.5.0 (исключая)
cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.0047
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 4.3
redhat
больше 3 лет назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
debian
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutr ...

CVSS3: 6.5
github
почти 3 года назад

openstack-neutron uncontrolled resource consumption flaw

EPSS

Процентиль: 64%
0.0047
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-400