Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpx3-696p-3cw9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpenStack Neutron Denial of Service vulnerability

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

Пакеты

Наименование

neutron

pip
Затронутые версииВерсия исправления

< 16.4.1

16.4.1

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 17.0.0, < 17.2.1

17.2.1

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 18.0.0, < 18.1.1

18.1.1

EPSS

Процентиль: 59%
0.00384
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-772

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

CVSS3: 6.5
redhat
больше 4 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

CVSS3: 6.5
nvd
больше 4 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

CVSS3: 6.5
debian
больше 4 лет назад

An issue was discovered in the routes middleware in OpenStack Neutron ...

EPSS

Процентиль: 59%
0.00384
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-772