Security controls bypass or absence In nova-lxd
Description
OpenStack Nova-LXD bypass security restrictions OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 13.1.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.