{"id":"GHSA-6xc7-4cx8-j3xc","summary":"OpenStack Nova-LXD bypass security restrictions","details":"OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.","aliases":["CVE-2017-5936","PYSEC-2017-21"],"modified":"2024-12-07T05:40:16.948826Z","published":"2022-05-13T01:46:20Z","database_specific":{"nvd_published_at":"2017-04-12T22:59:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-29T14:25:02Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5936"},{"type":"WEB","url":"https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2"},{"type":"WEB","url":"https://bugs.launchpad.net/nova-lxd/+bug/1656847"},{"type":"PACKAGE","url":"https://github.com/openstack/nova-lxd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nova-lxd/PYSEC-2017-21.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20200227193915/http://www.securityfocus.com/bid/96182"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2017/02/09/3"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-3195-1"}],"affected":[{"package":{"name":"nova-lxd","ecosystem":"PyPI","purl":"pkg:pypi/nova-lxd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"13.1.1"}]}],"versions":["0.19.0","13.0.0","13.0.0.0b2","13.0.0.0b3","13.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6xc7-4cx8-j3xc/GHSA-6xc7-4cx8-j3xc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}