Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 2279562

Summary: CVE-2023-6110 openstack-keystone: When a user tries to delete a non existing access rule, it deletes by accident another existing access rule in it's scope [openstack-17.1-rhel8-default]
Product: Red Hat OpenStack Reporter: Miguel Garcia <mgarciac>
Component: python-openstackclientAssignee: OSP Team <rhos-maint>
Status: CLOSED ERRATA QA Contact: Nobody <nobody>
Severity: medium Docs Contact:
Priority: medium    
Version: 17.1 (Wallaby)CC: apevec, askrabec, dmendiza, dwilde, jagee, jjoyce, jpichon, jschluet, lhh, mariel, millevy, oblaut, pgrist
Target Milestone: z3Keywords: Reopened, Security, SecurityTracking, Triaged
Target Release: 17.1   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: python-openstackclient-5.5.2-17.1.20230829213816.el8ost Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: 2209607 Environment:
Last Closed: 2024-05-22 20:11:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2209607    
Bug Blocks: 2212960    

Comment 7 MilanaLevy 2024-05-08 08:52:05 UTC
verified on 17.1-rhel9 and patch is present in the rhel8 build

Comment 14 errata-xmlrpc 2024-05-22 20:11:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: Red Hat OpenStack Platform 17.1 (python-openstackclient) security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2024:2769