Normal users can read machine details of owned machines

Bug #1811799 reported by Björn Tillenius
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
MAAS
Fix Released
High
Unassigned

Bug Description

This is with MAAS 2.5.1-7489-g2f25a2cc0-0ubuntu1~18.04.1.

Normal users can't see machines if they have a different
owner than themselves.

But if they know the system id, they can get the machine details:

  maas <login> machine details <system_id>

Tags: api rbac

Related branches

Changed in maas:
status: New → Triaged
importance: Undecided → High
milestone: none → 2.5.1
summary: - [2.5] Normal users can read machine details of owned machines
+ [2.5, API] Normal users can read machine details of owned machines
tags: added: api
Revision history for this message
Andres Rodriguez (andreserl) wrote : Re: [2.5, API] Normal users can read machine details of owned machines

I think this is an actual issue with non-RBAC MAAS too.

tags: added: rbac
Revision history for this message
Björn Tillenius (bjornt) wrote :

Yes, this is an issue with non-RBAC as well. That's why I didn't mention RBAC here.

Changed in maas:
milestone: 2.5.1 → 2.5.2
Changed in maas:
milestone: 2.5.2 → 2.5.3
Changed in maas:
milestone: 2.5.3 → 2.6.0beta2
Changed in maas:
milestone: 2.6.0beta2 → 2.6.0rc1
Changed in maas:
milestone: 2.6.0rc1 → 2.6.0rc2
Changed in maas:
milestone: 2.6.0rc2 → 2.7.0alpha1
Changed in maas:
milestone: 2.7.0b1 → 2.7.0b2
Changed in maas:
milestone: 2.7.0b2 → none
Alberto Donato (ack)
summary: - [2.5, API] Normal users can read machine details of owned machines
+ Normal users can read machine details of owned machines
Changed in maas:
milestone: none → 3.4.0
status: Triaged → Fix Committed
Alberto Donato (ack)
Changed in maas:
milestone: 3.4.0 → 3.4.0-beta1
Alberto Donato (ack)
Changed in maas:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.