VulnerabilityModified
CVE-2015-7713
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was…
MEDIUM 5.0EPSS 3.70%
Does this matter?
Lower severity and a low EPSS score (3.70%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.70% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- openstack/nova
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-2684.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76960Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2015:2673Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1491307Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1492961Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2015-021.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2684.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76960Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2015:2673Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1491307Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1492961Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2015-021.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.