QID 997504

Date Published: 2024-02-26

QID 997504: Python (Pip) Security Update for neutron (GHSA-cpx3-696p-3cw9)

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Github security advisory GHSA-cpx3-696p-3cw9 for updates and patch information.
    Vendor References

    CVEs related to QID 997504

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cpx3-696p-3cw9 neutron URL Logo github.com/advisories/GHSA-cpx3-696p-3cw9