Bug#1144989: trixie-pu: package aodh/20.0.0-2
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <aohRUygeejWGtGZw__35735.104656645$1787318729$gmane$org@eldamar.lan> |
On Fri, Aug 21, 2026 at 02:08:20PM +0200, Salvatore Bonaccorso wrote: > hi, > > On Fri, Aug 21, 2026 at 09:49:04AM +0200, Thomas Goirand wrote: > > Package: release.debian.org > > Severity: normal > > Tags: trixie > > X-Debbugs-Cc: [email protected] > > Control: affects -1 + src:aodh > > User: [email protected] > > Usertags: pu > > > > Hi, > > > > [ Reason ] > > I'd like to upload aodh 20.0.0-2+deb13u1, in order to address: > > https://security.openstack.org/ossa/OSSA-2026-036.html > > aka: > > https://bugs.debian.org/1144879 > > > > [ Impact ] > > As per upstream announce: > > Aodh does not enforce project scope on the > > alarm listing API when the all_projects query parameter is supplied with a > > false value. A non-admin user holding only the reader role can list alarms > > belonging to other projects, optionally targeting a specific project, exposing > > alarm metadata such as webhook action URLs, signal endpoints, and project > > identifiers. > > > > [ Tests ] > > I've run OpenStack functional testing on my CI, and Aodh appeared to > > continue working. On top of this, the patch includes new tests. I've > > also deployed the patched version in production in our public cloud. > > > > [ Risks ] > > Minimum: well tested, and small patch. > > > > [ Checklist ] > > [x] *all* changes are documented in the d/changelog > > [x] I reviewed all changes and I approve them > > [x] attach debdiff against the package in (old)stable > > [x] the issue is verified as fixed in unstable > > > > Please allow me to upload aodh/20.0.0-2+deb13u1 to p-u. > > > > Cheers, > > > > Thomas Goirand (zigo) > > > diff -Nru aodh-20.0.0/debian/changelog aodh-20.0.0/debian/changelog > > --- aodh-20.0.0/debian/changelog 2025-07-11 12:12:52.000000000 +0200 > > +++ aodh-20.0.0/debian/changelog 2026-08-12 09:57:24.000000000 +0200 > > @@ -1,3 +1,16 @@ > > +aodh (20.0.0-2+deb13u1) trixie; urgency=medium > > + > > + * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project > > + scope when the all_projects query parameter is present with a false value. > > + A non-admin project reader can list alarms belonging to other projects by > > + passing all_projects=false in a list query, optionally combined with a > > + foreign project_id to target a specific project. Leaked alarm data includes > > + trust webhook URLs, Heat signal endpoints, and project identifiers. Applied > > + upstream patch: "Fix all_projects=false bypass project scope" > > + (Closes: #1144879). > > This is CVE-2026-76878, can you please expand the changelog to note > it? One other thing, this does not look it is fixed in unstable yet? Did the upload maybe failed/got interruped? Regards, Salvatore