Comment 12 for bug 1872733

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

Oh, now I see Gage's suggestion to treat it as a class A report instead. Gage, what's the scenario where an authenticated user can exploit this without access to the victim's UUID?