CVE-2015-7713
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
EPSS 3.7%
描述
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
如何修補 CVE-2015-7713
要修補 CVE-2015-7713,請將受影響套件升級到下列已修補版本。
CVE-2015-7713 正在被利用嗎?
低 — EPSS 為 3.7%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2014.2.4
- from 0, < 2014.2.4, >= 2015.1.0, < 2015.1.2