Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-40797

Опубликовано: 08 сент. 2021
Источник: debian

Описание

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
neutronfixed2:19.0.0-1package
neutronfixed2:17.2.1-0+deb11u1bullseyepackage
neutronfixed2:13.0.7+git.2021.09.27.bace3d1890-0+deb10u1busterpackage

Примечания

  • https://launchpad.net/bugs/1942179

  • neutron-api in Debian is served over UWSGI, cf. https://bugs.debian.org/994202

  • and so serves the requests and stops the process.

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

CVSS3: 6.5
redhat
почти 5 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

CVSS3: 6.5
nvd
почти 5 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

CVSS3: 6.5
github
больше 4 лет назад

OpenStack Neutron Denial of Service vulnerability