CVE-2022-3277
published 2023-03-06CVE-2022-3277: An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for…
PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.06%
60.6th percentile
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2:21.0.0~rc1-3 (bookworm) | neutron 2:21.0.0~rc1-3 (bookworm) |
| openstack | neutron | < 18.6.0 | 18.6.0 |
| openstack | neutron | >= 0 < 2:21.0.0~rc1-3 | 2:21.0.0~rc1-3 |
| openstack | neutron | >= 0 < 2:21.0.0~rc1-3 | 2:21.0.0~rc1-3 |
| openstack | neutron | >= 0 < 2:21.0.0~rc1-3 | 2:21.0.0~rc1-3 |
| openstack | neutron | >= 0 < 18.6.0 | 18.6.0 |
| openstack | neutron | >= 0 < 2:12.1.1-0ubuntu8.1 | 2:12.1.1-0ubuntu8.1 |
| openstack | neutron | >= 0 < 2:16.4.2-0ubuntu6.2 | 2:16.4.2-0ubuntu6.2 |
| openstack | neutron | >= 0 < 2:20.3.0-0ubuntu1.1 | 2:20.3.0-0ubuntu1.1 |
| openstack | neutron | >= 19.0.0 < 19.5.0 | 19.5.0 |
| openstack | neutron | >= 19.0.0.0rc1 < 19.5.0 | 19.5.0 |
| openstack | neutron | >= 20.0.0.0rc1 < 20.3.0 | 20.3.0 |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
neutron vulnerabilities
osv·2023-05-10·CVSS 7.1
CVE-2021-20267 [HIGH] neutron vulnerabilities
neutron vulnerabilities
David Sinquin discovered that OpenStack Neutron incorrectly handled the
default Open vSwitch firewall rules. An attacker could possibly use this
issue to impersonate the IPv6 addresses of other systems on the network.
This issue only affected Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-20267)
Jake Yip and Justin Mammarella discovered that OpenStack Neutron
incorrectly handled the linuxbridge driver when ebtables-nft is being
used. An attacker could possibly use this issue to impersonate the hardware
addresss of other systems on the network. This issue only affected Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-38598)
Pavel Toporkov discovered that OpenStack Neutron incorrectly handled
extra_dhcp_opts values. An attacker could possibly use this issue to
OSV
openstack-neutron uncontrolled resource consumption flaw
osv·2023-03-07
CVE-2022-3277 [MEDIUM] openstack-neutron uncontrolled resource consumption flaw
openstack-neutron uncontrolled resource consumption flaw
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
GHSA
openstack-neutron uncontrolled resource consumption flaw
ghsa·2023-03-07
CVE-2022-3277 [MEDIUM] CWE-400 openstack-neutron uncontrolled resource consumption flaw
openstack-neutron uncontrolled resource consumption flaw
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
OSV
CVE-2022-3277: An uncontrolled resource consumption flaw was found in openstack-neutron
osv·2023-03-06·CVSS 6.5
CVE-2022-3277 [MEDIUM] CVE-2022-3277: An uncontrolled resource consumption flaw was found in openstack-neutron
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Red Hat
openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)
vendor_redhat·2023-07-12·CVSS 6.5
CVE-2023-3637 [MEDIUM] CWE-400 openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)
openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of ser
Ubuntu
OpenStack Neutron vulnerabilities
vendor_ubuntu·2023-05-10·CVSS 7.1
CVE-2021-20267 [HIGH] OpenStack Neutron vulnerabilities
Title: OpenStack Neutron vulnerabilities
Summary: Several security issues were fixed in OpenStack Neutron.
David Sinquin discovered that OpenStack Neutron incorrectly handled the
default Open vSwitch firewall rules. An attacker could possibly use this
issue to impersonate the IPv6 addresses of other systems on the network.
This issue only affected Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-20267)
Jake Yip and Justin Mammarella discovered that OpenStack Neutron
incorrectly handled the linuxbridge driver when ebtables-nft is being
used. An attacker could possibly use this issue to impersonate the hardware
addresss of other systems on the network. This issue only affected Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-38598)
Pavel Toporkov discovered that OpenStack Neutron incor
Red Hat
openstack-neutron: unrestricted creation of security groups
vendor_redhat·2022-08-29·CVSS 6.5
CVE-2022-3277 [MEDIUM] CWE-400 openstack-neutron: unrestricted creation of security groups
openstack-neutron: unrestricted creation of security groups
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Statement: While
Debian
CVE-2022-3277: neutron - An uncontrolled resource consumption flaw was found in openstack-neutron. This f...
vendor_debian·2022·CVSS 6.5
CVE-2022-3277 [MEDIUM] CVE-2022-3277: neutron - An uncontrolled resource consumption flaw was found in openstack-neutron. This f...
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Scope: local
bookworm: resolved (fixed in 2:21.0.0~rc1-3)
bullseye: open
forky: resolved (fixed in 2:21.0.0~rc1-3)
sid: resolved (fixed in 2:21.0.0~rc1-3)
trixie: resolved (fixed in 2:21.0.0~rc1-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-06
Published