Your message dated Thu, 06 Aug 2026 12:19:11 +0000
with message-id <[email protected]>
and subject line Bug#1143804: fixed in manila 1:22.0.0-4
has caused the Debian Bug report #1143804,
regarding OSSN-0103: Manila resource-lock list trusts a foreign project_id 
filter
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143804: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143804
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: manila
Version: 1:20.0.0-3
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce here:
https://wiki.openstack.org/wiki/OSSN/OSSN-0103

Summary:

A non-admin user with a project-scoped token can retrieve another project's
resource lock metadata by supplying a foreign project_id in the GET
/resource-locks request. The API only enforces the all-project policy check
when the all_projects parameter is present; without it, a user-supplied
project_id reaches the database filter unchanged, bypassing project scoping.

Affected Services / Software:

    manila: >=17.0.0 <20.0.2, >=21.0.0 <21.0.2, >=22.0.0 <22.0.1

Discussion:

Manila's resource-lock list API accepts an optional project UUID query
parameter. The ID is added as a filter and there is no verification whether
that the caller is authorized to view locks belonging to that project.

This allows any authenticated user with at least a reader role on any project
to retrieve resource lock metadata belonging to other projects. Access rule
lock information (deletion and visibility locks) is also exposed, since the
same filtering mechanism is reused.

The attack requires that the caller already possesses a valid project-scoped
token and knows the target project's UUID. Project UUIDs are not enumerable,
and therefore not guessable, which limits the practical impact.

A fix that adds an extra policy check to validate whether the caller belongs
to the supplied project has been merged.
Recommended Actions

Upgrade Manila to a version containing the fix
(https://review.opendev.org/998388) and restart the manila API services, or
apply the relevant patch to your deployment.

Patches:
The following reviews contain the fix for this issue:

    2026.2/hibiscus (development): https://review.opendev.org/998388
    2026.1/gazpacho: https://review.opendev.org/998567
    2025.2/flamingo: https://review.opendev.org/998568
    2025.1/epoxy: https://review.opendev.org/998569

Credits:

Chen YuXiang, Institute of Computing Technology, Chinese Academy of Sciences
Contacts / References

Authors:
    Carlos da Silva, Red Hat
    This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0103
    Original Launchpad bug:
        https://bugs.launchpad.net/manila/+bug/2161287
    Mailing List : [security-sig] tag on [email protected]
    OpenStack Security : https://security.openstack.org/
    CVE: none

--- End Message ---
--- Begin Message ---
Source: manila
Source-Version: 1:22.0.0-4
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
manila, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated manila package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 06 Aug 2026 13:43:30 +0200
Source: manila
Architecture: source
Version: 1:22.0.0-4
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1143804
Changes:
 manila (1:22.0.0-4) unstable; urgency=medium
 .
   * OSSN-0103: resource-lock list trusts a foreign project_id filter. Applied
     upstream patch: "Prevent unauthorized resource locks search".
     (Closes: #1143804)
Checksums-Sha1:
 1016525c99f7d05fd8f44f61a20efd17e53c94bf 3816 manila_22.0.0-4.dsc
 0e33793b8794f57d5aab231b23a361eeadae80c6 14408 manila_22.0.0-4.debian.tar.xz
 c35ad58ab2044920377f530753068e9d955ffaab 16782 manila_22.0.0-4_amd64.buildinfo
Checksums-Sha256:
 23f9ba68be44e8aee31c3d1e109bb0e9790b5ee80435b76f19450b530d3a5e46 3816 
manila_22.0.0-4.dsc
 c9e57d0bd70f6fdef284aa577bcee4447c23a4272c7843b41b36979c722b238a 14408 
manila_22.0.0-4.debian.tar.xz
 b8a3ad23a4a2d13372ab06c308f257c76c97480a26f30497751ca07d0e79e84a 16782 
manila_22.0.0-4_amd64.buildinfo
Files:
 abe9a420b2e4e6b4011fbeb9f6810e20 3816 net optional manila_22.0.0-4.dsc
 a5db373182ee7049d337947cdc83e835 14408 net optional 
manila_22.0.0-4.debian.tar.xz
 e02b7e48a633af99b3ad29171ed230b9 16782 net optional 
manila_22.0.0-4_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmp0eOYACgkQ1BatFaxr
Q/4lhRAAmshWvaW/KiYgZiHKu6E1/VgXR7N4ju/CDmspLcWF6Z+R202u1N6rrGTg
UV/MUFQpg7ehc2Q5i5GX+z2XQQdUc6uDFJbMp18fapoprCKo6h7d+gJAsmkDU8nq
bW50kqWROA1Jytipx0mEvbIECV2pQ5P+n3fwei6c7u9V46tIXkwEmBy8eP2kWN8E
WeQdboiZDwpZkpXsJ/prwVHlW+jfkO5FuQ/zf72u0fcCEwPJ0dCbR9upHKrpLKgW
wOxWhs47JWHtDkigajfJV2LwJvA62b90gxYhT8YpdG1+hL1IWvaZnP081haQfu8Y
bRQr/CHu2z9/KlBU5yEjT9HKh/NdavxpB163DwocWwQ86y9OGs4qjY+Phn4isFmv
q5e1I4q6jC975VFtyA9wZFHkb5R9ltENaMxZz2Vbo39RoijPMjr7Ca3WEjOk5i1w
9ZMUa2oV79lNqdUp3yUNLCeQaigVCXTzYMcMTW7++qojKNLtnfnbMXJ6PKCgu6Cg
PVaFRU2UKDCU2QcHtxNcLvhhT+yWAqp0o9yccmYGvf7NqZpilEpM019fa6oQCL2E
xdPJx8TEcUEVnx64R+fJOjKr0u52goyBDf8ukVO+DTn6twQtWycjNMI+YGSUt/46
zorex8bVs9stSzJNDH8FunRGCkvO98E1jg1vQG0cESjoZXGBBAk=
=c0Yn
-----END PGP SIGNATURE-----

Attachment: pgpCsMyMvhKCh.pgp
Description: PGP signature


--- End Message ---

Reply via email to