Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7713

Опубликовано: 05 окт. 2015
Источник: redhat
CVSS2: 5.5

Описание

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

A vulnerability was discovered in the way OpenStack Compute (nova) networking handled security group updates; changes were not applied to already running VM instances. A remote attacker could use this flaw to access running VM instances.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1269119openstack-nova: network security group changes are not applied to running instances

5.5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

nvd
больше 10 лет назад

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

debian
больше 10 лет назад

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 20 ...

github
больше 3 лет назад

OpenStack Compute (Nova) allows remote attackers to bypass intended restriction

suse-cvrf
около 10 лет назад

Security update for openstack-nova and openstack-neutron

5.5 Medium

CVSS2