Bug 2517803 (CVE-2026-76878)
| Summary: | CVE-2026-76878 aodh: python-watcher: aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | eglynn, jjoyce, jpretori, jschluet, lhh, mburns, mgarciac, security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in OpenStack Aodh and Watcher. In Aodh, the alarm listing API does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin authenticated user can list alarms belonging to other projects, potentially exposing alarm configurations, webhook URLs, and project identifiers. In Watcher, the webhook trigger endpoint does not enforce oslo.policy authorization, allowing any authenticated user who learns an audit webhook URL to trigger EVENT audits and associated action plans regardless of project or role.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2026-08-19 | ||
|
Description
OSIDB Bzimport
2026-08-18 12:12:03 UTC
|