Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-53916

Опубликовано: 25 нояб. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

РелизСтатусПримечание
devel

not-affected

2:26.0.0~b2+git2025011509.585ea689d5-0ubuntu2
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
noble

needed

oracular

ignored

end of life, was needed
plucky

not-affected

2:26.0.0~b2+git2025011509.585ea689d5-0ubuntu2
questing

not-affected

2:26.0.0~b2+git2025011509.585ea689d5-0ubuntu2

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

CVSS3: 7.5
nvd
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

CVSS3: 7.5
debian
около 1 года назад

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can ...

CVSS3: 7.5
github
около 1 года назад

OpenStack Neutron can use an incorrect ID during policy enforcement

7.5 High

CVSS3

Уязвимость CVE-2024-53916