REDHAT-BUG-1269119: Medium severity openstack compute (nova) vulnerability
Title: Nova network security group changes are not applied to running instances
Reporter: Sreekumar S and Suntao Products: Nova Affects: <=2014.2.3, >=2015.1.0, <=2015.1.1
Description:
Sreekumar S and Suntao independently reported a vulnerability in Nova network. Security group changes silently fail to be applied to already running instances, potentially resulting in instances not being protected by the security group. All Nova network setups are affected.
References:
https://launchpad.net/bugs/1491307 https://launchpad.net/bugs/1484738 http://seclists.org/oss-sec/2015/q4/41
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1269119?
The severity of REDHAT-BUG-1269119 is considered to be a medium risk due to security group changes not being applied to running instances.
How do I fix REDHAT-BUG-1269119?
To fix REDHAT-BUG-1269119, upgrade OpenStack Nova to a version later than 2015.1.1 or any version greater than 2014.2.3.
Which versions are affected by REDHAT-BUG-1269119?
REDHAT-BUG-1269119 affects OpenStack Nova versions up to and including 2014.2.3 and versions from 2015.1.0 to 2015.1.1.
What type of vulnerability is REDHAT-BUG-1269119?
REDHAT-BUG-1269119 is categorized as a configuration vulnerability impacting network security group changes.
Who reported REDHAT-BUG-1269119?
REDHAT-BUG-1269119 was reported independently by Sreekumar S and Suntao.