CVE-2023-3637 - CVE House
Back to Database
Status published Medium CVE-2023-3637

Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)

Vulnerability Description

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3637

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens) Operational Tools, Red Hat OpenStack Platform 16.1, Red Hat OpenStack Platform 17.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0
Vulnerable Versions:
1:15.3.5-2.20230216175503.el8ost

Timeline

Official Publish: July 25th, 2023
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)