Comment 2 for bug 1700501

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote :

Assuming this only affect localhost user and that rootwrap argument can not be set arbitrarily by remote user, I guess this is at best a class B2 or perhaps C1 according to VMT's taxonomy: https://security.openstack.org/vmt-process.html#incident-report-taxonomy

This also affects quite a few filters, e.g.: mount, tee, chown, dd, cp, chgrp, cat