CVE-2015-7713
Publication date 29 October 2015
Last updated 24 July 2024
Ubuntu priority
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
Status
Package | Ubuntu Release | Status |
---|---|---|
nova | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1:2014.1.5-0ubuntu1.7
|
|
Patch details
Package | Patch details |
---|---|
nova |
|
References
Related Ubuntu Security Notices (USN)
- USN-3449-1
- OpenStack Nova vulnerabilities
- 11 October 2017