CVE-2023-6110CWE-237

Openstack: deleting a non existing access rule deletes another existing access rule in it's scope

Medium · published November 17, 2024

CVSS v3.1
5.5
EPSS
0%
Percentile
40.6
In the wild
Unconfirmed
What it is

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00493 · 40.6th percentile
Weakness
CWE-237 · Improper Handling of Structural Elements
Published
2024-11-17T10:22Z
EPSS history
Timeline
  • 17 NOV 10:22Z
    Openstack: deleting a non existing access rule deletes another existing access rule in it's scope
    cvelistv5