Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)
Published Jul 25, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.31%
Description
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenStack Platform 13 (Queens) Operational Tools | affected |
|
- 13.0
- 16.2
No data.
Red Hat OpenStack Platform 16.2
openstack-neutron-1:15.3.5-2.20230216175503.el8ost
Fixed · RHSA-2023:4283
Red Hat OpenStack Platform 13 (Queens) Operational Tools
openstack-neutron
Will not fix
Red Hat OpenStack Platform 16.1
openstack-neutron
Not affected
Red Hat OpenStack Platform 17.0
openstack-neutron
Not affected
Red Hat OpenStack Platform 17.1
openstack-neutron
Not affected
Red Hat OpenStack Platform 18.0
openstack-neutron
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | openstack-neutron-1:15.3.5-2.20230216175503.el8ost | Fixed | RHSA-2023:4283 |
| Red Hat OpenStack Platform 13 (Queens) Operational Tools | openstack-neutron | Will not fix | n/a |
| Red Hat OpenStack Platform 16.1 | openstack-neutron | Not affected | n/a |
| Red Hat OpenStack Platform 17.0 | openstack-neutron | Not affected | n/a |
| Red Hat OpenStack Platform 17.1 | openstack-neutron | Not affected | n/a |
| Red Hat OpenStack Platform 18.0 | openstack-neutron | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While this vulnerability triggers the usage of API and Database resources, there is no action taken by OpenStack to enforce these new security group rules. As a result, the impact of this Denial of Service is rather limited. So deployments that have a strong trust relationship with all users (such as a private or company-internal OpenStack service) can consider this flaw as having a Low impact. Additionally, this vulnerability only affects deployments which provide direct access to their application programming interface (API). The command line interface (CLI) has had protections against this kind of misuse since at least Red Hat OpenStack Platform 13. - The patch associated with previous RHSA-2022:8855 for CVE-2022-3277, specifically for component openstack-neutron, was incorrect. A new CVE has been assigned to track the correct patch for this particular component.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 25, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.31% (0.01305) | 69.48th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.97% (0.00969) | 57.12th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.86% (0.00856) | 72.87th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.79% (0.02795) | 76.82th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.86% (0.00856) | 73.38th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.12% (0.00121) | 47.99th | v3 (v2023.03.01) |
| Jun 24, 2024 | 0.09% (0.00088) | 38.16th | v3 (v2023.03.01) |
| Aug 1, 2023 | 0.07% (0.00074) | 30.62th | v3 (v2023.03.01) |
| Jul 27, 2023 | 0.05% (0.00053) | 19.21th | v3 (v2023.03.01) |
| Jul 26, 2023 | 0.05% (0.00047) | 14.19th | v3 (v2023.03.01) |
References (6)
- https://access.redhat.com/errata/RHSA-2023:4283 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3637 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2222270 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-r3jh-qhgj-gvr8 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3637
- https://www.cve.org/CVERecord?id=CVE-2023-3637
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:4283 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-3637 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2222270 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-r3jh-qhgj-gvr8 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3637 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3637 |
Change history (0)
No recorded changes yet.