Описание
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
A flaw was found in OpenStack Aodh and Watcher. In Aodh, the alarm listing API does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin authenticated user can list alarms belonging to other projects, potentially exposing alarm configurations, webhook URLs, and project identifiers. In Watcher, the webhook trigger endpoint does not enforce oslo.policy authorization, allowing any authenticated user who learns an audit webhook URL to trigger EVENT audits and associated action plans regardless of project or role.
Отчет
Red Hat OpenStack Platform ships OpenStack Aodh as openstack-aodh in RHOSP 16.2, 17.1, and 18.0. RHOSP 16.2 is affected. That release does not receive this fix from upstream, and RHOSP 16.2 is in Extended Life Support Term 3. ELS3 only ships qualified Critical and Important RHSAs, plus Moderate CVEs with CVSS 7.0 or higher. This flaw is Moderate, so no security update is planned for 16.2. Red Hat OpenStack Services on OpenShift 18.0 ships OpenStack Watcher as the Optimize service. The /v1/webhooks/ endpoint is deployed and reachable on the same Watcher REST API as the rest of the service, and it cannot be bound to a separate network. Event-based audits cannot be disabled. They are always available. Red Hat documents only OneShot and Continuous audits as supported in RHOSO 18.0. Hardening may still be backported to 18.0. Event-based audits are planned for a later release.
Меры по смягчению последствий
Restrict network access to the Aodh API (default port 8042) and the Watcher API (default port 9322) to trusted administrative networks. Review Keystone role assignments to minimize users with project_reader or higher that can reach the Aodh API. The Watcher webhook path cannot be isolated from the main REST API. Keep enable_webhooks_auth=True (the default). Do not create or use event-based audits.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | openstack-aodh | Not affected | ||
| Red Hat OpenStack Platform 16.2 | openstack-aodh | Fix deferred | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-aodh-api | Out of support scope | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-aodh-base | Out of support scope | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-aodh-evaluator | Out of support scope | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-aodh-listener | Out of support scope | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-aodh-notifier | Out of support scope | ||
| Red Hat OpenStack Platform 17.1 | openstack-aodh | Fix deferred | ||
| Red Hat OpenStack Platform 18.0 | openstack-aodh | Fix deferred | ||
| Red Hat OpenStack Platform 18.0 | openstack-watcher | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.3 Medium
CVSS3
Связанные уязвимости
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked p...
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked poli
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project s ...
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked p...
EPSS
6.3 Medium
CVSS3