CVE-2021-40797

Description

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.384

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-38598,CVE-2021-40085,CVE-2021-40797 are fixed in Python-neutron 16.4.1Windows
Vulnerabilities CVE-2021-40085,CVE-2021-40797 are fixed in Python-neutron 17.2.1Windows
Vulnerabilities CVE-2021-40085,CVE-2021-40797 are fixed in Python-neutron 18.1.1Windows
OpenStack Virtual Network Service (USN-6067-1) python-neutron_12.1.1-0ubuntu8.1_all.debLinux
OpenStack Virtual Network Service (USN-6067-1) python3-neutron_16.4.2-0ubuntu6.2_all.debLinux
OpenStack Virtual Network Service (USN-6067-1) python3-neutron_20.3.0-0ubuntu1.1_all.debLinux
Vulnerabilities CVE-2021-38598,CVE-2021-40085,CVE-2021-40797 are fixed in Python-neutron for linux 16.4.1Linux
Vulnerabilities CVE-2021-40085,CVE-2021-40797 are fixed in Python-neutron for linux 17.2.1Linux
Vulnerabilities CVE-2021-40085,CVE-2021-40797 are fixed in Python-neutron for linux 18.1.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234