CVE Vulnerabilities

CVE-2021-40085

Published: Aug 31, 2021 | Modified: Jun 13, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Ubuntu
MEDIUM

An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.

Affected Software

Name Vendor Start Version End Version
Neutron Openstack * 16.4.1 (excluding)
Neutron Openstack 17.0.0 (including) 17.2.1 (excluding)
Neutron Openstack 18.0.0 (including) 18.1.1 (excluding)
Red Hat OpenStack Platform 10.0 (Newton) RedHat openstack-neutron-1:9.4.1-56.el7ost *
Red Hat OpenStack Platform 13.0 - ELS RedHat openstack-neutron-1:12.1.1-42.1.el7ost *
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS RedHat openstack-neutron-1:12.1.1-42.1.el7ost *
Red Hat OpenStack Platform 16.1 RedHat openstack-neutron-1:15.2.1-1.20210409073447.el8ost *
Red Hat OpenStack Platform 16.2 RedHat openstack-neutron-1:15.3.5-2.20210608154813.el8ost.3 *
Neutron Ubuntu bionic *
Neutron Ubuntu focal *
Neutron Ubuntu hirsute *
Neutron Ubuntu trusty *
Neutron Ubuntu upstream *
Neutron Ubuntu xenial *

References