Comment 3 for bug 1524274

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Unprivileged api user can access host data using instance snapshot

This seems like a similar issue of https://security.openstack.org/ossa/OSSA-2014-009.html

We did issue an advisory because nova user is able to read /etc/nova/nova.conf which usually contains sensitive information like services token.

Anyway, is this a regression or snapshot never used the disk info file to inspect file format ?