Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3277

Опубликовано: 29 авг. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Отчет

While this vulnerability triggers the usage of API and Database resources, there is no action taken by OpenStack to enforce these new security group rules. As a result, the impact of this Denial of Service is rather limited. So deployments that have a strong trust relationship with all users (such as a private or company-internal OpenStack service) can consider this flaw as having a Low impact. Additionally, this vulnerability only affects deployments which provide direct access to their application programming interface (API). The command line interface (CLI) has had protections against this kind of misuse since at least Red Hat OpenStack Platform 13.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-neutronAffected
Red Hat OpenStack Platform 16.1openstack-neutronFixedRHSA-2022:887007.12.2022
Red Hat OpenStack Platform 16.2openstack-neutronFixedRHSA-2022:885507.12.2022
Red Hat OpenStack Platform 17.0openstack-neutronFixedRHSA-2023:027525.01.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2129193openstack-neutron: unrestricted creation of security groups

EPSS

Процентиль: 64%
0.0047
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
nvd
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 6.5
debian
почти 3 года назад

An uncontrolled resource consumption flaw was found in openstack-neutr ...

CVSS3: 6.5
github
почти 3 года назад

openstack-neutron uncontrolled resource consumption flaw

EPSS

Процентиль: 64%
0.0047
Низкий

4.3 Medium

CVSS3