Your message dated Mon, 24 Aug 2026 14:35:30 +0000
with message-id <[email protected]>
and subject line Bug#1144879: fixed in aodh 22.0.0-3
has caused the Debian Bug report #1144879,
regarding aodh: CVE-2026-76878: OSSA-2026-036: cross-project alarm enumeration
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144879: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144879
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: aodh
Version: 20.0.0-2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce:
https://security.openstack.org/ossa/OSSA-2026-036.html


Date:
    August 19, 2026
CVE:
    CVE-2026-pending

Affects:
    Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
    Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2

Description:

Chen YuXiang of the Institute of Computing Technology, Chinese Academy of
Sciences reported that OpenStack Aodh does not enforce project scope on the
alarm listing API when the all_projects query parameter is supplied with a
false value. A non-admin user holding only the reader role can list alarms
belonging to other projects, optionally targeting a specific project, exposing
alarm metadata such as webhook action URLs, signal endpoints, and project
identifiers. All Aodh deployments are affected.

The same reporter found that OpenStack Watcher does not apply authorization to
its webhook trigger endpoint. Any authenticated user who learns an audit’s
webhook URL, for example from the Aodh alarm metadata leaked above, can start
an EVENT audit and its associated action plan regardless of their own project
or role. All Watcher deployments are affected.

Patches:
    https://review.opendev.org/1001503 (2025.1/epoxy (aodh))
    https://review.opendev.org/1001509 (2025.1/epoxy (watcher))
    https://review.opendev.org/1001502 (2025.2/flamingo (aodh))
    https://review.opendev.org/1001508 (2025.2/flamingo (watcher))
    https://review.opendev.org/1001501 (2026.1/gazpacho (aodh))
    https://review.opendev.org/1001507 (2026.1/gazpacho (watcher))
    https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh))
    https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher))

Credits:
    Chen YuXiang from Institute of Computing Technology, Chinese Academy
of Sciences

References:
    https://launchpad.net/bugs/2161276
    https://launchpad.net/bugs/2161771
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes:
    A CVE identifier was requested from MITRE for the aodh vulnerability on
2026-08-03. The CVE will be added to this advisory by errata once assigned.

--- End Message ---
--- Begin Message ---
Source: aodh
Source-Version: 22.0.0-3
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
aodh, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated aodh package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 12 Aug 2026 09:52:46 +0200
Source: aodh
Architecture: source
Version: 22.0.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1144879
Changes:
 aodh (22.0.0-3) unstable; urgency=high
 .
   * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project
     scope when the all_projects query parameter is present with a false value.
     A non-admin project reader can list alarms belonging to other projects by
     passing all_projects=false in a list query, optionally combined with a
     foreign project_id to target a specific project. Leaked alarm data includes
     trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
     upstream patch: "Fix all_projects=false bypass project scope"
     (Closes: #1144879).
Checksums-Sha1:
 3bd1b94b8580af7c5df0a2c4add5ac16863ab492 3532 aodh_22.0.0-3.dsc
 0d0f799311aca291c1cd9cfcd6791c8f464a2602 13444 aodh_22.0.0-3.debian.tar.xz
 e08793efee0a5db1a2c53a4d987cbe8ae73c5f1a 17600 aodh_22.0.0-3_amd64.buildinfo
Checksums-Sha256:
 165778b0999339843f7c1f904a7c8f85e1c50f05b990332393be3e5c2ea085c8 3532 
aodh_22.0.0-3.dsc
 f864ba03bd4b945b5279a3c5be823715be4dc134b7ed11842a6e63392200a603 13444 
aodh_22.0.0-3.debian.tar.xz
 dc7b2d53b69a146579d81657bd5c37d58d3509c08def31540556cd58a8f28ff9 17600 
aodh_22.0.0-3_amd64.buildinfo
Files:
 b479d26a723ca5169cdbca4653b17aed 3532 web optional aodh_22.0.0-3.dsc
 d4342762b689f2953c6e4b75befe6ba5 13444 web optional aodh_22.0.0-3.debian.tar.xz
 35e453ec4fbf3c0284afe233e2e6e64e 17600 web optional 
aodh_22.0.0-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqMTw8ACgkQ1BatFaxr
Q/7yGQ//dcbAwfsI7AlxmUM3gdfbFijMGuq47Y+wURmvSMWdKWj3mwvuCQYceJl8
zjSI89nCjsxSB+XoCREjIgROpGefJDUPO6U67QJVXIDYK5KGqzuDwPWRE9llZNIM
11/Qi+yjic/w8TjG6OzIIQ8NIIOeZUSdIkC1Au/7ZXbrb7obRE12X8iuXomrNbj3
Sjow5bxtRZ2bQRBtlyul4/zwQqq3oKtnMgTqwzqUA16j9A6MC61AcqRhcc8gKtpr
p5KC0xzUEioM8VwyIcB4jMSisELgneH1dBNhsZWxEoCF98s/07bNyL0v5dGmJikP
BmJnfAsc3oCd/7TrZBtiD9wVuMhO6v5oiPzMZPkgI+eSkAp1W5Ij38r51sj0EV3U
eO59M0NQKVQ3loTY/gU7sXSkFFtJzvYR40m2IEEkymZ6NDgn13em6eZ8vZyFCeIW
O6CbQBroRgdo2p8ZBE7s5kh2NOtb3kURadqbd0KJxCp0mnujbUqI39rYhQKc9S/X
iRqY0Q9ABYcAWVkhyApK7fh45xpn/fj0HozQOduhZ6nOh5vEZY//kxfBY1Kcztx6
Vv2JJ+NDos0d31p1kSy0tNHK8qgTuQHCBMIGsy+dZWRM5h5w0QTJP0Q3fLFC5Csx
TLZ36ir72E0mygBPD1O7BRDi+lwuWNbO95Aa9S8EnaPdQBOAjOo=
=rZ8B
-----END PGP SIGNATURE-----

Attachment: pgpYSom3E5dMm.pgp
Description: PGP signature


--- End Message ---

Reply via email to