On 12/1/24 17:31, Moritz Mühlenhoff wrote:
Source: neutron
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for neutron.

CVE-2024-53916[0]:
| In OpenStack Neutron through 25.0.0, neutron/extensions/tagging.py
| can use an incorrect ID during policy enforcement. NOTE: 935883 has
| the "Work in Progress" status as of 2024-11-24.

https://review.opendev.org/c/openstack/neutron/+/935883


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-53916
     https://www.cve.org/CVERecord?id=CVE-2024-53916

Please adjust the affected versions in the BTS as needed.

Hi moritz,

Since the patch that introduced the bug was merged in Oct 19, 2023, Neutron was never affected in any stable release of Debian. Please update the security tracker accordingly.

Cheers,

Thomas Goirand (zigo)

Reply via email to