356
VMScore

CVE-2021-40797

Published: 08/09/2021 Updated: 15/09/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in the routes middleware in OpenStack Neutron prior to 16.4.1, 17.x prior to 17.2.1, and 18.x prior to 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack neutron

Vendor Advisories

Debian Bug report logs - #994202 neutron: CVE-2021-40797: Routes middleware memory leak for nonexistent controllers Package: src:neutron; Maintainer for src:neutron is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 13 Sep 2021 17:33:02 UTC Severi ...
Synopsis Moderate: Red Hat OpenStack Platform 162 (openstack-neutron) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-neutron is now available for Red Hat OpenStackPlatform 162 (Tr ...
Synopsis Moderate: Red Hat OpenStack Platform 161 (openstack-neutron) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-neutron is now available for Red Hat OpenStackPlatform 161 (Tr ...
An issue was discovered in the routes middleware in OpenStack Neutron before 1641, 17x before 1721, and 18x before 1811 By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service ...