Comment 2 for bug 2048111

Revision history for this message
Jeremy Stanley (fungi) wrote (last edit ):

Since this report concerns a possible security risk, an incomplete
security advisory task has been added while the core security
reviewers for the affected project or projects confirm the bug and
discuss the scope of any vulnerability along with potential
solutions.

Based on the reporter's assertion that this condition is only exploitable by cloud administrators, I don't think an embargo is warranted and this can just be treated as a hardening opportunity, class D in our report taxonomy: https://security.openstack.org/vmt-process.html#report-taxonomy

I included both Horizon and Keystone as it's not clear to me where the mitigation would occur.