Source: blazar
Version: 17.0.0-2
Severity: important
Tags: security upstream
Forwarded: https://launchpad.net/bugs/2162719
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for blazar.
CVE-2026-93852[0]:
| In OpenStack Blazar before 17.0.1, the V2 lease listing operation
| (GET /v2/leases) returns leases for every project without enforcing
| project scoping or an administrator-only policy. Any authenticated
| user with access to the Blazar REST API can enumerate leases
| belonging to other tenants, exposing lease IDs, reservation IDs,
| resource IDs, and reservation metadata. The exposed lease IDs also
| enable the object-level authorization bypass tracked in the
| companion request, allowing an attacker to then modify or delete the
| enumerated leases.
CVE-2026-93854[1]:
| In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce
| object-level authorization on its update and delete operations (PUT
| /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy
| authorize() wrapper attempts to load the target lease to build the
| authorization target from its owner, but it looks up the lease under
| the keyword "lease_id" whereas the controller methods name the
| parameter "id" (and the wsme_pecan.wsexpose wrapper delivers it
| positionally). The lookup returns None, and thus authorization falls
| back to the requesting user's own project_id/user_id instead of the
| target lease owner. Any authenticated user who knows a lease ID can
| therefore modify or delete leases belonging to other users and
| projects, bypassing the intended ownership check.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-93852
https://www.cve.org/CVERecord?id=CVE-2026-93852
[1] https://security-tracker.debian.org/tracker/CVE-2026-93854
https://www.cve.org/CVERecord?id=CVE-2026-93854
[2] https://launchpad.net/bugs/2162719
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore