In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
Update neutron to 28.0.1; neutron to 27.0.3; neutron to 26.0.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanOpenStack Neutron has an Incorrect Authorization issue affects neutron (pip), neutron (pip), neutron (pip). Severity is medium. In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
AI coding agents often install or upgrade packages automatically in pip. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| neutronpip | >=28.0.0,<28.0.1 | 28.0.1 |
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
Update neutron to 28.0.1; neutron to 27.0.3; neutron to 26.0.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanOpenStack Neutron has an Incorrect Authorization issue affects neutron (pip), neutron (pip), neutron (pip). Severity is medium. In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
AI coding agents often install or upgrade packages automatically in pip. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| neutronpip | >=28.0.0,<28.0.1 | 28.0.1 |
| neutronpip | >=27.0.0,<27.0.3 | 27.0.3 |
|---|
| neutronpip | >=26.0.0,<26.0.4 | 26.0.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| neutronpip | >=27.0.0,<27.0.3 | 27.0.3 |
|---|
| neutronpip | >=26.0.0,<26.0.4 | 26.0.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard