OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "13.1.0"
}
],
"source": "CPE_RANGE",
"vendor_product": "openstack:nova-lxd",
"cpes": [
"cpe:2.3:a:openstack:nova-lxd:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "16.04"
}
],
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "canonical:ubuntu_linux"
}
]
}