openstack-neutron: unrestricted creation of security groups
Published Mar 6, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.06%
Description
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Affected products
- Vendor n/a Product Openstack-Neutron Defaultn/a
- Version As shipped with Red Hat Openstack 13, 16.1, and 16.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Openstack-Neutron | n/a |
|
- < 18.6.0
- ≥ 19.0.0 · < 19.5.0
- 13.0
- 16.1
- 16.2
No data.
Red Hat OpenStack Platform 16.1
openstack-neutron-1:15.2.1-1.20221005123225.40d217c.el8ost
Fixed · RHSA-2022:8870
Red Hat OpenStack Platform 16.2
openstack-neutron-1:15.3.5-2.20221005184727.c81fb5b.el8ost
Fixed · RHSA-2022:8855
Red Hat OpenStack Platform 17.0
openstack-neutron-1:18.4.1-0.20221128170741.5258354.el9ost
Fixed · RHSA-2023:0275
Red Hat OpenStack Platform 13 (Queens)
openstack-neutron
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | openstack-neutron-1:15.2.1-1.20221005123225.40d217c.el8ost | Fixed | RHSA-2022:8870 |
| Red Hat OpenStack Platform 16.2 | openstack-neutron-1:15.3.5-2.20221005184727.c81fb5b.el8ost | Fixed | RHSA-2022:8855 |
| Red Hat OpenStack Platform 17.0 | openstack-neutron-1:18.4.1-0.20221128170741.5258354.el9ost | Fixed | RHSA-2023:0275 |
| Red Hat OpenStack Platform 13 (Queens) | openstack-neutron | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While this vulnerability triggers the usage of API and Database resources, there is no action taken by OpenStack to enforce these new security group rules. As a result, the impact of this Denial of Service is rather limited. So deployments that have a strong trust relationship with all users (such as a private or company-internal OpenStack service) can consider this flaw as having a Low impact. Additionally, this vulnerability only affects deployments which provide direct access to their application programming interface (API). The command line interface (CLI) has had protections against this kind of misuse since at least Red Hat OpenStack Platform 13.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-3277 Vendor Advisory
- https://bugs.launchpad.net/neutron/+bug/1988026 exploitIssue TrackingPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=2129193 exploitIssue TrackingPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1125 Advisory
- https://github.com/advisories/GHSA-w446-h7vg-wv3p Advisory
- https://github.com/openstack/neutron/commit/01fc2b9195f999df4d810df4ee63f77ecbc81f7e
- https://github.com/openstack/neutron/commit/717e3e09556f1fb9a7a420863746fa785eb6c316
- https://github.com/openstack/neutron/commit/733ef4f2d8c2a3734c360d1c1dd3a6fcd600cb8c
- https://github.com/openstack/neutron/commit/cbeee87fa44cd200d4997e02042098460167dce1
- https://github.com/openstack/neutron/commit/d0e1b54fb1de932b2b30ab4269cf5789632df476
- https://github.com/openstack/neutron/commit/fd7fb0e9d8c602380f54975367d935ab69e10c05
- https://nvd.nist.gov/vuln/detail/CVE-2022-3277
- https://www.cve.org/CVERecord?id=CVE-2022-3277
Change history (0)
No recorded changes yet.