VYPR
Medium severity6.5NVD Advisory· Published Mar 6, 2023· Updated Jun 17, 2026

CVE-2022-3277

CVE-2022-3277

Description

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
neutronPyPI
>= 19.0.0.0rc1, < 19.5.019.5.0
neutronPyPI
< 18.6.018.6.0
neutronPyPI
>= 20.0.0.0rc1, < 20.3.020.3.0

Affected products

6
  • OpenStack/Neutron2 versions
    cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*range: <18.6.0
    • (no CPE)
  • Red Hat/Openstack3 versions
    cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 19.0.0.0rc1, < 19.5.0

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.