PT-2021-22954 · Openstack+3 · Openstack Neutron+3

Slawek Kaplonski

·

Published

2021-09-08

·

Updated

2024-08-07

·

CVE-2021-40797

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Neutron versions prior to 16.4.1 OpenStack Neutron versions 17.x prior to 17.2.1 OpenStack Neutron versions 18.x prior to 18.1.1
Description An issue in the routes middleware allows an authenticated user to cause API performance degradation or denial of service by making API requests involving nonexistent controllers, resulting in the API worker consuming increasing amounts of memory.
Recommendations For OpenStack Neutron versions prior to 16.4.1, update to version 16.4.1 or later. For OpenStack Neutron versions 17.x prior to 17.2.1, update to version 17.2.1 or later. For OpenStack Neutron versions 18.x prior to 18.1.1, update to version 18.1.1 or later.

Exploit

Fix

DoS

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10658
ALT-PU-2024-1575
CVE-2021-40797
GHSA-CPX3-696P-3CW9
PYSEC-2021-329
RHSA-2022:0990
RHSA-2022:0996
SUSE-SU-2022:1884-1
USN-6067-1

Affected Products

Alt Linux
Linuxmint
Openstack Neutron
Ubuntu