CVE-2015-7713
Last modified
CVE-2015-7713 is a vulnerability of currently unknown severity. OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.. EPSS estimates a 3.67% chance of exploitation in the next 30 days.
Description
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Nova | >= 2014.2, < 2014.2.4 |
| Openstack | Nova | >= 2015.1.0, < 2015.1.2 |
References
- http://rhn.redhat.com/errata/RHSA-2015-2684.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76960Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2015:2673Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1491307Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1492961Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2015-021.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2684.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76960Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2015:2673Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1491307Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/1492961Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2015-021.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7713?
How severe is CVE-2015-7713?
How do I fix CVE-2015-7713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7706Multiple cross-site scripting (XSS) vulnerabilities in Secur…
- CVE-2015-7707Ignite Realtime Openfire 3.10.2 allows remote authenticated …
- CVE-2015-7708Cross-site scripting (XSS) vulnerability in 4images 1.7.11 a…
- CVE-2015-7709The arkeiad daemon in the Arkeia Backup Agent in Western Dig…
- CVE-2015-7711Cross-site scripting (XSS) vulnerability in popuphelp.php in…
- CVE-2015-7712Multiple eval injection vulnerabilities in mods/_standard/gr…
- CVE-2015-7714Multiple SQL injection vulnerabilities in the Realtyna RPL (…7.2
- CVE-2015-7715Cross-site request forgery (CSRF) vulnerability in the Realt…8.8
- CVE-2015-7716libstagefright in Android 5.x before 5.1.1 LMY48T allows rem…
- CVE-2015-7717mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 befor…
- CVE-2015-7718mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 befor…
- CVE-2015-7723AMD fglrx-driver before 15.7 allows local users to gain priv…
Are you affected by CVE-2015-7713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
