{"api_version":"1","generated_at":"2026-07-23T07:41:08+00:00","cve":"CVE-2015-7713","urls":{"html":"https://cve.report/CVE-2015-7713","api":"https://cve.report/api/cve/CVE-2015-7713.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7713","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7713"},"summary":{"title":"CVE-2015-7713","description":"OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.","state":"PUBLISHED","assigner":"redhat","published_at":"2015-10-29 20:59:09","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-254","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2015:2673","name":"https://access.redhat.com/errata/RHSA-2015:2673","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76960","name":"http://www.securityfocus.com/bid/76960","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"OpenStack Nova CVE-2015-7713 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugs.launchpad.net/nova/+bug/1491307","name":"https://bugs.launchpad.net/nova/+bug/1491307","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Bug #1491307 “[OSSA 2015-021] secgroup rules doesn't work for in...” : Bugs : OpenStack Compute (nova)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.openstack.org/ossa/OSSA-2015-021.html","name":"https://security.openstack.org/ossa/OSSA-2015-021.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"OSSA-2015-021: Nova network security group changes are not applied to running instances — OpenStack Security Advisories 2014.2.0.dev125 documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-2684.html","name":"http://rhn.redhat.com/errata/RHSA-2015-2684.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://bugs.launchpad.net/nova/+bug/1492961","name":"https://bugs.launchpad.net/nova/+bug/1492961","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Bug #1492961 “Security Group Rules not effective immediately” : Bugs : OpenStack Compute (nova)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2015:2684","name":"MISC:https://access.redhat.com/errata/RHSA-2015:2684","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:0013","name":"MISC:https://access.redhat.com/errata/RHSA-2016:0013","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:0017","name":"MISC:https://access.redhat.com/errata/RHSA-2016:0017","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2015-7713","name":"MISC:https://access.redhat.com/security/cve/CVE-2015-7713","refsource":"MITRE","tags":[],"title":"CVE-2015-7713 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1269119","name":"MISC:https://bugzilla.redhat.com/show_bug.cgi?id=1269119","refsource":"MITRE","tags":[],"title":"1269119 – (CVE-2015-7713) CVE-2015-7713 openstack-nova: network security group changes are not applied to running instances","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7713","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7713","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7713","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"nova","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:58:59.895Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"76960","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76960"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.launchpad.net/nova/+bug/1491307"},{"name":"RHSA-2015:2673","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2015:2673"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.launchpad.net/nova/+bug/1492961"},{"name":"RHSA-2015:2684","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-2684.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://security.openstack.org/ossa/OSSA-2015-021.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-10-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-05T14:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"76960","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76960"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.launchpad.net/nova/+bug/1491307"},{"name":"RHSA-2015:2673","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2015:2673"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.launchpad.net/nova/+bug/1492961"},{"name":"RHSA-2015:2684","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-2684.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://security.openstack.org/ossa/OSSA-2015-021.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2015-7713","datePublished":"2015-10-29T20:00:00.000Z","dateReserved":"2015-10-06T00:00:00.000Z","dateUpdated":"2024-08-06T07:58:59.895Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-10-29 20:59:09","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-254","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*","versionStartIncluding":"2014.2","versionEndExcluding":"2014.2.4","matchCriteriaId":"8E483493-8EAA-4772-85E6-8F05C8F0C9F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*","versionStartIncluding":"2015.1.0","versionEndExcluding":"2015.1.2","matchCriteriaId":"6F2937D9-1DB2-4C70-B5AA-E9E847090F6E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7713","Ordinal":"1","Title":"CVE-2015-7713","CVE":"CVE-2015-7713","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7713","Ordinal":"1","NoteData":"OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.","Type":"Description","Title":"CVE-2015-7713"},{"CveYear":"2015","CveId":"7713","Ordinal":"2","NoteData":"2015-10-29","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7713","Ordinal":"3","NoteData":"2016-12-05","Type":"Other","Title":"Modified"}]}}}