Back

MEDIUM

Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)

Published Jul 25, 2023

Description

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Affected products

Remediation

Red Hat statement

While this vulnerability triggers the usage of API and Database resources, there is no action taken by OpenStack to enforce these new security group rules. As a result, the impact of this Denial of Service is rather limited. So deployments that have a strong trust relationship with all users (such as a private or company-internal OpenStack service) can consider this flaw as having a Low impact. Additionally, this vulnerability only affects deployments which provide direct access to their application programming interface (API). The command line interface (CLI) has had protections against this kind of misuse since at least Red Hat OpenStack Platform 13. - The patch associated with previous RHSA-2022:8855 for CVE-2022-3277, specifically for component openstack-neutron, was incorrect. A new CVE has been assigned to track the correct patch for this particular component.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 25, 2023
Updated Nov 20, 2025
Reserved Jul 12, 2023
CISA Vulnrichment
Updated Apr 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 12, 2023
GHSA-R3JH-QHGJ-GVR8