CVE-2017-5936
Published: 8 February 2017
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
Priority
CVSS 3 base score: 7.5
Notes
Author | Note |
---|---|
tyhicks | Only affects xenial-mitaka |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5936
- https://ubuntu.com/security/notices/USN-3195-1
- NVD
- Launchpad
- Debian