REDHAT-BUG-1508539: Medium severity Openstack Nova vulnerability
By rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected.
Affected versions: <=14.0.9, >=15.0.0 <=15.0.7, >=16.0.0 <=16.0.2
Bug report:
https://launchpad.net/bugs/1664931
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1508539?
The severity of REDHAT-BUG-1508539 is classified as a medium risk due to the potential circumvention of security filters.
How do I fix REDHAT-BUG-1508539?
To fix REDHAT-BUG-1508539, upgrade your OpenStack Nova to versions 15.0.8 or higher and ensure proper filter configurations.
Who is affected by REDHAT-BUG-1508539?
All setups using the Nova Filter Scheduler in OpenStack versions 14.0.9 and 15.0.0 to 15.0.7 are affected by REDHAT-BUG-1508539.
What systems are impacted by REDHAT-BUG-1508539?
The systems impacted by REDHAT-BUG-1508539 include any OpenStack Nova deployments that utilize the Filter Scheduler feature.
What is the nature of the vulnerability in REDHAT-BUG-1508539?
The vulnerability in REDHAT-BUG-1508539 allows authenticated users to bypass imposed filters when rebuilding instances.