VDB
BDU%3A2024-10195
BDU%3A2024-10195
PUBLISHED
CVSS 5.5 MEDIUM
Уязвимость компонента Access Rule Handler платформы облачных сервисов Red Hat OpenStack Platform, позволяющая нарушителю выполнить отказ в обслуживании
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenStack Platform 17.0 | |
| Red Hat | Red Hat OpenStack Platform 17.1 for RHEL 9 | 0:5.5.2-17.1.20230829210830.el9ost |
| Red Hat | Red Hat OpenStack Platform 16.1 | |
| Canonical Ltd., Сообщество свободного программного обеспечения, ООО «Ред Софт», Red Hat Inc. | Ubuntu, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat OpenStack Platform | |
| Red Hat | Red Hat OpenStack Platform 17.1 for RHEL 8 | 0:5.5.2-17.1.20230829213816.el8ost |
| Red Hat | Red Hat OpenStack Platform 16.2 | |
| Red Hat | Red Hat OpenStack Platform 18.0 |
Timeline
- Jan 25, 2024 PoC Published
- Nov 17, 2024 CVE Published
- Nov 17, 2024 PoC Published
- Nov 17, 2024 PoC Published
- Nov 25, 2024 CVE Updated
- May 30, 2026 Distribution Patch
- May 30, 2026 Distribution Patch
- May 30, 2026 Security Advisory
- May 30, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2023-6110 url
- https://redos.red-soft.ru/support/secure/ url
- https://ubuntu.com/security/CVE-2023-6110 url
- https://security-tracker.debian.org/tracker/CVE-2023-6110 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- RHSA-2024:2737 vendor-advisory
- RHSA-2024:2769 vendor-advisory
- RHBZ#2212960 issue
- https://code.engineering.redhat.com/gerrit/gitweb?p=python-openstackclient.git;a=commit;h=7a7c364bdd7b2cd2b56e73724110710a68d58abf url
- https://review.opendev.org/c/openstack/python-openstackclient/+/888697 url