PT-2026-44555 · Openstack · Openstack Neutron
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Neutron versions 26.0.0 through 28.0.0
Description
The tagging controller enforces plural policy action names on single-tag write operations, whereas the defined policy rules use singular names. This mismatch causes the default policy to evaluate the actions as allowed, enabling a project reader to create and update tags on resources within the same project.
Recommendations
Update to version 28.0.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Neutron