Back

MEDIUM

openstack-neutron: unrestricted creation of security groups

Published Mar 6, 2023

Description

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Affected products

Remediation

Red Hat statement

While this vulnerability triggers the usage of API and Database resources, there is no action taken by OpenStack to enforce these new security group rules. As a result, the impact of this Denial of Service is rather limited. So deployments that have a strong trust relationship with all users (such as a private or company-internal OpenStack service) can consider this flaw as having a Low impact. Additionally, this vulnerability only affects deployments which provide direct access to their application programming interface (API). The command line interface (CLI) has had protections against this kind of misuse since at least Red Hat OpenStack Platform 13.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 6, 2023
Updated Mar 7, 2025
Reserved Sep 22, 2022
CISA Vulnrichment
Updated Mar 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 29, 2022
ENISA EUVD
Assigner redhat
Published Mar 6, 2023
Updated Mar 7, 2025
Exploited since n/a
EUVD-2023-1125 GHSA-W446-H7VG-WV3P