Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3637

Опубликовано: 12 июл. 2023
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Отчет

While this vulnerability triggers the usage of API and Database resources, there is no action taken by OpenStack to enforce these new security group rules. As a result, the impact of this Denial of Service is rather limited. So deployments that have a strong trust relationship with all users (such as a private or company-internal OpenStack service) can consider this flaw as having a Low impact. Additionally, this vulnerability only affects deployments which provide direct access to their application programming interface (API). The command line interface (CLI) has had protections against this kind of misuse since at least Red Hat OpenStack Platform 13.

  • The patch associated with previous RHSA-2022:8855 for CVE-2022-3277, specifically for component openstack-neutron, was incorrect. A new CVE has been assigned to track the correct patch for this particular component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens) Operational Toolsopenstack-neutronWill not fix
Red Hat OpenStack Platform 16.1openstack-neutronNot affected
Red Hat OpenStack Platform 17.0openstack-neutronNot affected
Red Hat OpenStack Platform 17.1openstack-neutronNot affected
Red Hat OpenStack Platform 18.0openstack-neutronNot affected
Red Hat OpenStack Platform 16.2openstack-neutronFixedRHSA-2023:428326.07.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2222270openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)

EPSS

Процентиль: 44%
0.00214
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 4.3
nvd
больше 2 лет назад

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

CVSS3: 4.3
debian
больше 2 лет назад

An uncontrolled resource consumption flaw was found in openstack-neutr ...

CVSS3: 6.5
github
больше 2 лет назад

Denial of service in neutron

EPSS

Процентиль: 44%
0.00214
Низкий

4.3 Medium

CVSS3