Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)
Vulnerability Description
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3637
Credits & Attribution
No credits recorded in the NVD database.
References
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →