Beschreibung
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller-s project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects- instances, aka cross-tenant denial of service.
CVSS 6.3EPSS 0.20600000000000002%Risiko 0.64
Quelle öffnen- Veröffentlicht
- 2026-05-07 22:16:35
- Betroffene Versionen
- <16.0.1
- Typ
- Core software
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L