Incorrect Permission Assignment for Critical Resource Affecting neutron package, versions [24.0.0,]
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-NEUTRON-8400870
- published 25 Nov 2024
- disclosed 24 Nov 2024
- credit Unknown
Introduced: 24 Nov 2024
New CVE-2024-53916 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
neutron is an OpenStack project to provide “network connectivity as a service” between interface devices (e.g., vNICs) managed by other OpenStack services (e.g., nova). It implements the Neutron API.
Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource due to the reliance on a caller ID during policy enforcement, rather than using the parent/resource ID.