Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-6110", "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "state": "PUBLISHED", "assignerShortName": "redhat", "dateReserved": "2023-11-13T19:27:25.305Z", "datePublished": "2024-11-17T10:22:34.776Z", "dateUpdated": "2024-12-05T20:30:27.043Z"}, "containers": {"cna": {"affected": [{"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:openstack:17.1::el8"], "defaultStatus": "affected", "packageName": "python-openstackclient", "product": "Red Hat OpenStack Platform 17.1 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.5.2-17.1.20230829213816.el8ost", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:openstack:17.1::el9"], "defaultStatus": "affected", "packageName": "python-openstackclient", "product": "Red Hat OpenStack Platform 17.1 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.5.2-17.1.20230829210830.el9ost", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:openstack:16.1"], "defaultStatus": "affected", "packageName": "openstack-keystone", "product": "Red Hat OpenStack Platform 16.1", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:openstack:16.2"], "defaultStatus": "affected", "packageName": "openstack-keystone", "product": "Red Hat OpenStack Platform 16.2", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:openstack:17.0"], "defaultStatus": "unknown", "packageName": "openstack-keystone", "product": "Red Hat OpenStack Platform 17.0", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:openstack:18.0"], "defaultStatus": "affected", "packageName": "openstack-keystone", "product": "Red Hat OpenStack Platform 18.0", "vendor": "Red Hat"}], "datePublic": "2024-01-24T00:00:00+00:00", "descriptions": [{"lang": "en", "value": "A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials."}], "metrics": [{"other": {"content": {"namespace": "https://access.redhat.com/security/updates/classification/", "value": "Moderate"}, "type": "Red Hat severity rating"}}, {"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "version": "3.1"}, "format": "CVSS"}], "providerMetadata": {"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat", "dateUpdated": "2024-12-05T20:30:27.043Z"}, "references": [{"name": "RHSA-2024:2737", "tags": ["vendor-advisory", "x_refsource_REDHAT"], "url": "https://access.redhat.com/errata/RHSA-2024:2737"}, {"name": "RHSA-2024:2769", "tags": ["vendor-advisory", "x_refsource_REDHAT"], "url": "https://access.redhat.com/errata/RHSA-2024:2769"}, {"tags": ["vdb-entry", "x_refsource_REDHAT"], "url": "https://access.redhat.com/security/cve/CVE-2023-6110"}, {"name": "RHBZ#2212960", "tags": ["issue-tracking", "x_refsource_REDHAT"], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2212960"}, {"url": "https://code.engineering.redhat.com/gerrit/gitweb?p=python-openstackclient.git;a=commit;h=7a7c364bdd7b2cd2b56e73724110710a68d58abf"}, {"url": "https://review.opendev.org/c/openstack/python-openstackclient/+/888697"}], "problemTypes": [{"descriptions": [{"cweId": "CWE-237", "description": "Improper Handling of Structural Elements", "lang": "en", "type": "CWE"}]}], "x_redhatCweChain": "CWE-237: Improper Handling of Structural Elements", "timeline": [{"lang": "en", "time": "2023-06-05T00:00:00+00:00", "value": "Reported to Red Hat."}, {"lang": "en", "time": "2024-01-24T00:00:00+00:00", "value": "Made public."}], "title": "Openstack: deleting a non existing access rule deletes another existing access rule in it's scope"}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-11-17T16:17:28.263809Z", "id": "CVE-2023-6110", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-11-26T14:38:40.898Z"}}]}}