Moderate severityNVD Advisory· Published Oct 29, 2015· Updated May 6, 2026
CVE-2015-7713
CVE-2015-7713
Description
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
novaPyPI | < 2014.2.4 | 2014.2.4 |
novaPyPI | >= 2015.1.0, < 2015.1.2 | 2015.1.2 |
Affected products
6- ghsa-coords6 versionspkg:pypi/novapkg:rpm/suse/openstack-neutron&distro=SUSE%20Cloud%20Compute%20Node%20for%20SUSE%20Linux%20Enterprise%2012%205pkg:rpm/suse/openstack-nova&distro=SUSE%20Cloud%20Compute%20Node%20for%20SUSE%20Linux%20Enterprise%2012%205pkg:rpm/suse/openstack-nova&distro=SUSE%20OpenStack%20Cloud%205pkg:rpm/suse/openstack-nova-doc&distro=SUSE%20OpenStack%20Cloud%205pkg:rpm/suse/python-python-memcached&distro=SUSE%20Cloud%20Compute%20Node%20for%20SUSE%20Linux%20Enterprise%2012%205
< 2014.2.4+ 5 more
- (no CPE)range: < 2014.2.4
- (no CPE)range: < 2014.2.4~a0~dev103-10.3
- (no CPE)range: < 2014.2.4~a0~dev80-14.1
- (no CPE)range: < 2014.2.4~a0~dev80-20.1
- (no CPE)range: < 2014.2.4~a0~dev80-20.1
- (no CPE)range: < 1.54-2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- rhn.redhat.com/errata/RHSA-2015-2684.htmlnvdThird Party AdvisoryWEB
- www.securityfocus.com/bid/76960nvdThird Party AdvisoryVDB EntryWEB
- access.redhat.com/errata/RHSA-2015:2673nvdThird Party AdvisoryWEB
- bugs.launchpad.net/nova/+bug/1491307nvdThird Party AdvisoryWEB
- bugs.launchpad.net/nova/+bug/1492961nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-67rh-9p29-vrxrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-7713ghsaADVISORY
- security.openstack.org/ossa/OSSA-2015-021.htmlnvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2015:2684ghsaWEB
- access.redhat.com/errata/RHSA-2016:0013ghsaWEB
- access.redhat.com/errata/RHSA-2016:0017ghsaWEB
- access.redhat.com/security/cve/CVE-2015-7713ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- opendev.org/openstack/novaghsaPACKAGE
- web.archive.org/web/20200228024902/http://www.securityfocus.com/bid/76960ghsaWEB
News mentions
0No linked articles in our index yet.