Source: aodh
Version: 20.0.0-2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce:
https://security.openstack.org/ossa/OSSA-2026-036.html


Date:
    August 19, 2026
CVE:
    CVE-2026-pending

Affects:
    Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
    Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2

Description:

Chen YuXiang of the Institute of Computing Technology, Chinese Academy of
Sciences reported that OpenStack Aodh does not enforce project scope on the
alarm listing API when the all_projects query parameter is supplied with a
false value. A non-admin user holding only the reader role can list alarms
belonging to other projects, optionally targeting a specific project, exposing
alarm metadata such as webhook action URLs, signal endpoints, and project
identifiers. All Aodh deployments are affected.

The same reporter found that OpenStack Watcher does not apply authorization to
its webhook trigger endpoint. Any authenticated user who learns an audit’s
webhook URL, for example from the Aodh alarm metadata leaked above, can start
an EVENT audit and its associated action plan regardless of their own project
or role. All Watcher deployments are affected.

Patches:
    https://review.opendev.org/1001503 (2025.1/epoxy (aodh))
    https://review.opendev.org/1001509 (2025.1/epoxy (watcher))
    https://review.opendev.org/1001502 (2025.2/flamingo (aodh))
    https://review.opendev.org/1001508 (2025.2/flamingo (watcher))
    https://review.opendev.org/1001501 (2026.1/gazpacho (aodh))
    https://review.opendev.org/1001507 (2026.1/gazpacho (watcher))
    https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh))
    https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher))

Credits:
    Chen YuXiang from Institute of Computing Technology, Chinese Academy
of Sciences

References:
    https://launchpad.net/bugs/2161276
    https://launchpad.net/bugs/2161771
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes:
    A CVE identifier was requested from MITRE for the aodh vulnerability on
2026-08-03. The CVE will be added to this advisory by errata once assigned.

Reply via email to