Safety vulnerability ID: 59931
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Neutron 23.0.0.0b2 and prior versions have a Denial of Service vulnerability. An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
https://github.com/advisories/GHSA-r3jh-qhgj-gvr8
Latest version: 26.0.0
OpenStack Networking
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service. See CVE-2023-3637.
MISC:RHBZ#2222270: https://bugzilla.redhat.com/show_bug.cgi?id=2222270
MISC:https://access.redhat.com/security/cve/CVE-2023-3637: https://access.redhat.com/security/cve/CVE-2023-3637
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application