Openstack: deleting a non existing access rule deletes another existing access rule in it's scope
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.5epss 0.5%
probabilidad de explotación
0.5%top 60% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Productos afectados
Red Hat · Red Hat OpenStack Platform 16.1Red Hat · Red Hat OpenStack Platform 16.2Red Hat · Red Hat OpenStack Platform 17.0Red Hat · Red Hat OpenStack Platform 17.1 for RHEL 8Red Hat · Red Hat OpenStack Platform 17.1 for RHEL 9Red Hat · Red Hat OpenStack Platform 18.0Referencias
https://access.redhat.com/errata/RHSA-2024:2737https://access.redhat.com/errata/RHSA-2024:2769https://access.redhat.com/security/cve/CVE-2023-6110https://bugzilla.redhat.com/show_bug.cgi?id=2212960https://code.engineering.redhat.com/gerrit/gitweb?p=python-openstackclient.git;a=commit;h=7a7c364bdd7b2cd2b56e73724110710a68d58abfhttps://review.opendev.org/c/openstack/python-openstackclient/+/888697