PT-2024-35973 · Openstack · Openstack Neutron

Tore Anderson

·

Published

2024-11-24

·

Updated

2025-01-06

·

CVE-2024-53916

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: OpenStack Neutron versions 23 through 23.2.0 OpenStack Neutron versions 24 through 24.0.1 OpenStack Neutron versions 25 through 25.0.0
Description: The issue affects OpenStack Neutron, where the neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. This results in the failure to apply the proper policy check for changing network tags. As a consequence, an unprivileged tenant can change (add and clear) tags on network objects that do not belong to the tenant without being subjected to the proper policy authorization check.
Recommendations: For OpenStack Neutron versions 23 through 23.2.0, update to version 23.2.1 or later. For OpenStack Neutron versions 24 through 24.0.1, update to version 24.0.2 or later. For OpenStack Neutron versions 25 through 25.0.0, update to version 25.0.1 or later.

Fix

Insufficient Verification of Data Authenticity

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2024-53916
GHSA-F27H-G923-68HW

Affected Products

Openstack Neutron