Debian Security Update DSA-3953 aodh - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,787
Reaction score
74
Credits
-1,257
Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an authenticated user without a Keystone token with knowledge of trust IDs to perform unspecified authenticated actions by adding alarm actions.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top