Impact
OpenStack Octavia up to version 18.0.0 incorrectly handles authorization for quality of service policies. By associating a QoS policy from another project with an amphora, an authenticated user can prevent that policy from being deleted. The result is an unprivileged user can persist unwanted or insecure QoS configurations. The weakness is an authorization bypass (CWE-863).
Affected Systems
All Octavia deployments using OpenStack Octavia up to and including version 18.0.0 are affected. The issue impacts the Octavia component that manages amphora resources and their QoS policy associations.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not listed in CISA's KEV catalog. Attackers only need authenticated access to Octavia and can associate an external QoS policy to an amphora to prevent its deletion. This does not grant higher privileges but allows an attacker to keep unwanted QoS policies in place.
OpenCVE Enrichment