PYSEC-2017-21

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/nova-lxd/PYSEC-2017-21.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2017-21
Aliases
Published
2017-04-12T22:59:00Z
Modified
2024-04-29T14:56:48.394548Z
Summary
[none]
Details

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

References

Affected packages

PyPI / nova-lxd

Package

Affected ranges

Type
GIT
Repo
https://github.com/openstack/nova-lxd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.1.1

Affected versions

0.*

0.19.0

13.*

13.0.0.0b2
13.0.0.0b3
13.0.0
13.1.0