Arbitrary Code Execution Affecting nova-lxd package, versions [,13.1.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-NOVALXD-40458
  • published31 Jan 2017
  • disclosed31 Jan 2017
  • creditJames Page

Introduced: 31 Jan 2017

CVE-2017-5936  (opens in a new tab)
CWE-254  (opens in a new tab)

Overview

nova_lxd is a native lxd driver for openstack OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

CVSS Base Scores

version 3.1