Comment 6 for bug 1872733

Revision history for this message
Gage Hugo (gagehugo) wrote : Re: Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

Thanks cmurphy for the quick fix, looks good and works for me locally.

With the verification here and fix, this is looking like a Class A vulnerability according to the VMT taxonomy[0]. Even with the requirement to know/guess UUIDs, this looks to be something that is exploitable by any authenticated user.

[0] https://security.openstack.org/vmt-process.html#incident-report-taxonomy