ZeroHour

CVE-2017-5936

CVSS 3.0
7.5 high
EPSS
3%p86
Published
()
Modified
Description

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

Vendors
canonicalopenstack
Products
ubuntu linux, nova-lxd
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.