---
title: "CVE-2015-7713\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-7713?format=md
keywords: index, follow
---

# CVE-2015-7713

Publication date 29 October 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before
2015.1.2 (kilo) do not properly apply security group changes, which allows
remote attackers to bypass intended restriction by leveraging an instance
that was running when the change was made.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| nova | 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Fixed 1:2014.1.5-0ubuntu1.7 |
| 12.04 LTS precise | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2015-7713?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| nova | * Upstream:   <https://review.openstack.org/222026> * Upstream:   <https://review.openstack.org/222023> * Upstream:   <https://review.openstack.org/222022> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7713)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-7713)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-7713)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-7713)

### Related Ubuntu Security Notices (USN)

+ [USN-3449-1](https://usn.ubuntu.com/USN-3449-1)
+ OpenStack Nova vulnerabilities
+ 11 October 2017

### Other references

* <http://www.openwall.com/lists/oss-security/2015/10/05/10>
* <http://lists.openstack.org/pipermail/openstack-announce/2015-October/000683.html>
* <https://www.cve.org/CVERecord?id=CVE-2015-7713>
