CVE-2023-6110: Red Hat Openstack Platform 16.1

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

Affected products

  • Red Hat Red Hat Openstack Platform 16.1
  • Red Hat Red Hat Openstack Platform 16.2
  • Red Hat Red Hat Openstack Platform 17.0
  • Red Hat Red Hat Openstack Platform 17.1 For Rhel 8: before 0:5.5.2-17.1.20230829213816.el8ost (fixed in 0:5.5.2-17.1.20230829213816.el8ost)
  • Red Hat Red Hat Openstack Platform 17.1 For Rhel 9: before 0:5.5.2-17.1.20230829210830.el9ost (fixed in 0:5.5.2-17.1.20230829210830.el9ost)
  • Red Hat Red Hat Openstack Platform 18.0

Published 2024-11-17. Last modified 2026-06-17.