Skip to main content

Improper Handling of Structural Elements

CVE-2023-6110

Severity Medium
Score 5.5/10

Summary

A flaw was found in OpenStack versions through 5.8.0, 6.0.0, and 6.1.0 through 6.2.0. When a user tries to delete a non-existing access rule in its scope, it deletes other existing access rules that are not associated with any application credentials.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • REQUIRED
  • LOW
  • LOW
  • LOW

CWE-237 - Improper Handling of Structural Elements

The software does not handle or incorrectly handles inputs that are related to complex structures.

Advisory Timeline

  • Published