CVE-2021-40085
Summary
| CVE | CVE-2021-40085 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-31 18:15:00 UTC |
| Updated | 2022-06-13 19:56:00 UTC |
| Description | An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Openstack | Neutron | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3027-1] neutron security update | MLIST | lists.debian.org | |
| OSSA-2021-005: Arbitrary dnsmasq reconfiguration via extra_dhcp_opts — OpenStack Security Advisories 0.0.1.dev241 documentation | MISC | security.openstack.org | |
| [SECURITY] [DLA 2781-1] neutron security update | MLIST | lists.debian.org | |
| oss-security - [OSSA-2021-005] Neutron: Arbitrary dnsmasq reconfiguration via extra_dhcp_opts (CVE-2021-40085) | MLIST | www.openwall.com | |
| Bug #1939733 “[OSSA-2021-005] Arbitrary dnsmasq reconfiguration ...” : Bugs : neutron | MISC | launchpad.net | |
| Debian -- Security Information -- DSA-4983-1 neutron | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178820 Debian Security Update for neutron (DSA 4983-1)
- 178836 Debian Security Update for neutron (DLA 2781-1)
- 179321 Debian Security Update for neutron (DLA 3027-1)
- 182336 Debian Security Update for neutron (CVE-2021-40085)
- 199327 Ubuntu Security Notification for OpenStack Neutron Vulnerabilities (USN-6067-1)
- 239622 Red Hat Update for Red Hat OpenStack Platform 13.0 (openstack-neutron) (RHSA-2021:3503)
- 239623 Red Hat Update for Red Hat OpenStack Platform 10.0 (openstack-neutron) (RHSA-2021:3502)
- 239634 Red Hat Update for Red Hat OpenStack Platform 16.1 (openstack-neutron) (RHSA-2021:3481)
- 239640 Red Hat Update for Red Hat OpenStack Platform 16.2 (openstack-neutron) (RHSA-2021:3488)
- 997506 Python (Pip) Security Update for neutron (GHSA-fh73-gjvg-349c)