Bugzilla – Bug 1213276
VUL-0: CVE-2023-3637: openstack-neutron: unrestricted creation of security groups
Last modified: 2023-07-13 07:47:48 UTC
CVE-2023-3637 An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3637 https://bugzilla.redhat.com/show_bug.cgi?id=2222270
CVSS < 7.0, so won't fix for Cloud8 and Cloud9 codestreams, which are the only ones with openstack-neutron. Closing.