Debian Security Advisory 3953-1

Discussion in 'News Aggregator' started by Packet Storm, 25 Aug 2017.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3953-1 - Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an authenticated users without a Keystone token with knowledge of trust IDs to perform unspecified authenticated actions by adding alarm actions.

    Continue reading...
     

Share This Page

Loading...