Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. neutron
  4. ›
  5. CVE-2024-53916

CVE-2024-53916: OpenStack Neutron can use an incorrect ID during policy enforcement

November 25, 2024 (updated January 9, 2025)

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.

References

  • github.com/advisories/GHSA-f27h-g923-68hw
  • github.com/openstack/neutron
  • github.com/openstack/neutron/blob/363ffa6e9e1ab5968f87d45bc2f1cb6394f48b9f/neutron/extensions/tagging.py
  • nvd.nist.gov/vuln/detail/CVE-2024-53916
  • review.opendev.org/c/openstack/neutron/+/935883
  • review.opendev.org/q/project:openstack/neutron
  • security.openstack.org/ossa/OSSA-2024-005.html

Code Behaviors & Features

Detect and mitigate CVE-2024-53916 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 23.0.0 before 23.2.1, all versions starting from 24.0.0 before 24.0.2, all versions starting from 25.0.0 before 25.0.1

Fixed versions

  • 23.2.1
  • 24.0.2
  • 25.0.1

Solution

Upgrade to versions 23.2.1, 24.0.2, 25.0.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-345: Insufficient Verification of Data Authenticity
  • CWE-754: Improper Check for Unusual or Exceptional Conditions

Source file

pypi/neutron/CVE-2024-53916.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:57 +0000.