First published: Wed Nov 01 2017(Updated: )
By rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Affected versions: <=14.0.9, >=15.0.0 <=15.0.7, >=16.0.0 <=16.0.2 Bug report: <a href="https://launchpad.net/bugs/1664931">https://launchpad.net/bugs/1664931</a>
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Compute (Nova) | <=14.0.9>=15.0.0<=15.0.7>=16.0.0<=16.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1508539 is classified as a medium risk due to the potential circumvention of security filters.
To fix REDHAT-BUG-1508539, upgrade your OpenStack Nova to versions 15.0.8 or higher and ensure proper filter configurations.
All setups using the Nova Filter Scheduler in OpenStack versions 14.0.9 and 15.0.0 to 15.0.7 are affected by REDHAT-BUG-1508539.
The systems impacted by REDHAT-BUG-1508539 include any OpenStack Nova deployments that utilize the Filter Scheduler feature.
The vulnerability in REDHAT-BUG-1508539 allows authenticated users to bypass imposed filters when rebuilding instances.