VDB
KO
MEDIUM 6.5

GHSA-w446-h7vg-wv3p

openstack-neutron uncontrolled resource consumption flaw

Details

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / neutron
Introduced in: 19.0.0.0rc1 Fixed in: 19.5.0
Fix pip install --upgrade 'neutron>=19.5.0'
PyPI / neutron
Introduced in: 0 Fixed in: 18.6.0
Fix pip install --upgrade 'neutron>=18.6.0'
PyPI / neutron
Introduced in: 20.0.0.0rc1 Fixed in: 20.3.0
Fix pip install --upgrade 'neutron>=20.3.0'

References