In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1.
                
            References
                    Configurations
                    No configuration.
History
                    06 Jan 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-754 | 
04 Dec 2024, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | |
| Summary | (en) In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is not subjected to the proper policy authorization check. This affects 23 before 23.2.1, 24 before 24.0.2, and 25 before 25.0.1. | 
27 Nov 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
25 Nov 2024, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-11-25 00:15
Updated : 2025-01-06 18:15
NVD link : CVE-2024-53916
Mitre link : CVE-2024-53916
CVE.ORG link : CVE-2024-53916
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-754
                        
            Improper Check for Unusual or Exceptional Conditions
