VYPR
Moderate severityNVD Advisory· Published Oct 29, 2015· Updated May 6, 2026

CVE-2015-7713

CVE-2015-7713

Description

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
novaPyPI
< 2014.2.42014.2.4
novaPyPI
>= 2015.1.0, < 2015.1.22015.1.2

Affected products

6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.