Количество 4
Количество 4
CVE-2026-40214
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.
CVE-2026-40214
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.
CVE-2026-40214
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API d ...
GHSA-mmpc-xjxr-5hf8
OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40214 In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-40214 In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-40214 In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API d ... | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
GHSA-mmpc-xjxr-5hf8 OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer | CVSS3: 6.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу