Openstack: deleting a non existing access rule deletes another existing access rule in it's scope
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.5epss 0.5%
probabilidade de exploração
0.5%top 60% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Produtos afetados
Red Hat · Red Hat OpenStack Platform 16.1Red Hat · Red Hat OpenStack Platform 16.2Red Hat · Red Hat OpenStack Platform 17.0Red Hat · Red Hat OpenStack Platform 17.1 for RHEL 8Red Hat · Red Hat OpenStack Platform 17.1 for RHEL 9Red Hat · Red Hat OpenStack Platform 18.0Referências
https://access.redhat.com/errata/RHSA-2024:2737https://access.redhat.com/errata/RHSA-2024:2769https://access.redhat.com/security/cve/CVE-2023-6110https://bugzilla.redhat.com/show_bug.cgi?id=2212960https://code.engineering.redhat.com/gerrit/gitweb?p=python-openstackclient.git;a=commit;h=7a7c364bdd7b2cd2b56e73724110710a68d58abfhttps://review.opendev.org/c/openstack/python-openstackclient/+/888697