Safety vulnerability ID: 41251
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Neutron 16.4.1, 17.2.1 and 18.1.1 include a fix for CVE-2021-40085: An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
https://www.openwall.com/lists/oss-security/2021/08/31/2
Latest version: 27.0.1
OpenStack Networking
              An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value. See CVE-2021-40085.
MISC:https://launchpad.net/bugs/1939733: https://launchpad.net/bugs/1939733
MISC:https://security.openstack.org/ossa/OSSA-2021-005.html: https://security.openstack.org/ossa/OSSA-2021-005.html
MLIST:[oss-security] 20210831 [OSSA-2021-005] Neutron: Arbitrary dnsmasq reconfiguration via extra_dhcp_opts (CVE-2021-40085): http://www.openwall.com/lists/oss-security/2021/08/31/2
            
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application