CVE-2023-3637: Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3637?
CVE-2023-3637 is an uncontrolled resource consumption flaw in openstack-neutron.
How does CVE-2023-3637 affect users?
CVE-2023-3637 allows a remote authenticated user to query a list of security groups for an invalid project, creating unconstrained resources.
What is the severity of CVE-2023-3637?
The severity of CVE-2023-3637 is medium, with a CVSS score of 6.5.
Which software versions are affected by CVE-2023-3637?
Versions up to and including 22.0.2 of the neutron package from pip, Redhat Openstack Platform 13.0, and Redhat Openstack Platform 16.2 are affected by CVE-2023-3637.
How can I fix CVE-2023-3637?
Update to a version of the neutron package from pip, Redhat Openstack Platform 13.0, or Redhat Openstack Platform 16.2 that is not affected by CVE-2023-3637.