Comment 9 for bug 1376915

Revision history for this message
Matthew Edmonds (edmondsw) wrote : Re: Ceilometer policy file settings ignored

Audit data is highly sensitive. Saying that all users on a project can view the audit data for that project has to be considered a security vulnerability. This being "the intended behavior" just means someone didn't think things through very well, not that it isn't a security vulnerability... and a bad one at that.