[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3953-1 aodh -- aodh

ID: oval:org.secpod.oval:def:603072Date: (C)2017-08-31   (M)2022-08-31
Class: PATCHFamily: unix




Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an authenticated users without a Keystone token with knowledge of trust IDs to perform unspecified authenticated actions by adding alarm actions.

Platform:
Debian 9.x
Product:
aodh-doc
aodh-evaluator
python-aodh
aodh-expirer
aodh-listener
aodh-common
aodh-notifier
aodh-api
Reference:
DSA-3953-1
CVE-2017-12440
CVE    1
CVE-2017-12440
CPE    3
cpe:/a:github:aodh-common
cpe:/o:debian:debian_linux:9.x
cpe:/a:github:python-aodh

© SecPod Technologies