PT-2024-35973 · Openstack · Openstack Neutron
Tore Anderson
·
Published
2024-11-24
·
Updated
2025-01-06
·
CVE-2024-53916
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenStack Neutron versions 23 through 23.2.0
OpenStack Neutron versions 24 through 24.0.1
OpenStack Neutron versions 25 through 25.0.0
Description:
The issue affects OpenStack Neutron, where the neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. This results in the failure to apply the proper policy check for changing network tags. As a consequence, an unprivileged tenant can change (add and clear) tags on network objects that do not belong to the tenant without being subjected to the proper policy authorization check.
Recommendations:
For OpenStack Neutron versions 23 through 23.2.0, update to version 23.2.1 or later.
For OpenStack Neutron versions 24 through 24.0.1, update to version 24.0.2 or later.
For OpenStack Neutron versions 25 through 25.0.0, update to version 25.0.1 or later.
Fix
Insufficient Verification of Data Authenticity
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Neutron