Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7713

Опубликовано: 05 окт. 2015
Источник: redhat
CVSS2: 5.5
EPSS Низкий

Описание

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

A vulnerability was discovered in the way OpenStack Compute (nova) networking handled security group updates; changes were not applied to already running VM instances. A remote attacker could use this flaw to access running VM instances.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1269119openstack-nova: network security group changes are not applied to running instances

EPSS

Процентиль: 89%
0.0367
Низкий

5.5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

nvd
почти 11 лет назад

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

debian
почти 11 лет назад

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 20 ...

github
больше 4 лет назад

OpenStack Compute (Nova) allows remote attackers to bypass intended restriction

suse-cvrf
больше 10 лет назад

Security update for openstack-nova and openstack-neutron

EPSS

Процентиль: 89%
0.0367
Низкий

5.5 Medium

CVSS2