Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6110

Опубликовано: 24 янв. 2024
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.1openstack-keystoneAffected
Red Hat OpenStack Platform 16.2openstack-keystoneAffected
Red Hat OpenStack Platform 17.0openstack-keystoneOut of support scope
Red Hat OpenStack Platform 18.0openstack-keystoneAffected
Red Hat OpenStack Platform 17.1 for RHEL 8python-openstackclientFixedRHSA-2024:276922.05.2024
Red Hat OpenStack Platform 17.1 for RHEL 9python-openstackclientFixedRHSA-2024:273722.05.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-237
https://bugzilla.redhat.com/show_bug.cgi?id=2212960openstack: deleting a non existing access rule deletes another existing access rule in it's scope

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
7 месяцев назад

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

CVSS3: 5.5
nvd
7 месяцев назад

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

CVSS3: 5.5
debian
7 месяцев назад

A flaw was found in OpenStack. When a user tries to delete a non-exist ...

CVSS3: 5.5
redos
7 месяцев назад

Уязвимость python3-openstackclient

CVSS3: 5.5
github
7 месяцев назад

OpenStack improperly deletes access rules

5.5 Medium

CVSS3