Race-Condition Flaw in OpenStack Neutron by Red Hat
CVE-2017-7543
5.3MEDIUM
Summary
A race-condition vulnerability exists in OpenStack Neutron that can disable security groups during a minor overcloud update. This flaw leads to the reset of critical parameters, allowing unauthorized access to tenant virtual machines and network resources. Attackers could exploit this condition to compromise the security of cloud environments, particularly when these updates are implemented, increasing the need for vigilance and prompt remediation measures.
Affected Version(s)
openstack-neutron openstack-neutron-10.0.2-1.1
openstack-neutron openstack-neutron-8.3.0-11.1
openstack-neutron openstack-neutron-9.3.1-2.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved