Cue

user supplied network is not validated before attaching

Bug #1466609 reported by Min Pae
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Cue
Fix Released
High
Min Pae

Bug Description

The network specified by a user during cluster creation is not validated to ensure that the user has ownership or access to the network. This can lead to users attaching a VM to arbitrary networks. This may not be an issue currently due to the single network/port limitation Cue currently has but if/when multi-network attachment is supported this could lead to security issues where a user can attach to networks they should not have access to.

Min Pae (sputnik13)
Changed in cue:
status: New → Triaged
importance: Critical → High
Revision history for this message
Min Pae (sputnik13) wrote :

Ownership/access to a network should be defined as

1) network is a shared network

or

2) network is owned by tenant requesting cluster creation

Changed in cue:
assignee: nobody → Min Pae (sputnik13)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to cue (master)

Fix proposed to branch: master
Review: https://review.openstack.org/224751

Changed in cue:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to cue (master)

Reviewed: https://review.openstack.org/224751
Committed: https://git.openstack.org/cgit/openstack/cue/commit/?id=13493f7cefee8c4eafb29eaf60fa81119ec9a1f7
Submitter: Jenkins
Branch: master

commit 13493f7cefee8c4eafb29eaf60fa81119ec9a1f7
Author: Min Pae <email address hidden>
Date: Wed Sep 16 09:38:57 2015 -0700

    validate network information during cluster create

    Change-Id: I466173ac7f8a8f91db51ccbdbaa437b37a9d0ad4
    Closes-Bug: 1466609

Changed in cue:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.