CVE-2024-53916

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.
Configurations

No configuration.

History

04 Dec 2024, 04:15

Type Values Removed Values Added
Summary (en) In OpenStack Neutron through 25.0.0, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. NOTE: 935883 has the "Work in Progress" status as of 2024-11-24. (en) In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

04 Dec 2024, 02:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/12/03/1 -

27 Nov 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) En OpenStack Neutron hasta la versión 25.0.0, neutron/extensions/tagging.py puede usar una ID incorrecta durante la aplicación de políticas. NOTA: 935883 tiene el estado "Trabajo en progreso" al 24/11/2024.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

25 Nov 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-25 00:15

Updated : 2024-12-04 04:15


NVD link : CVE-2024-53916

Mitre link : CVE-2024-53916

CVE.ORG link : CVE-2024-53916


JSON object : View

Products Affected

No product.

CWE

No CWE.