In affected Aodh versions, a non-admin user with only the reader role can list alarms belonging to other projects by supplying the all_projects query parameter with a false value. They can optionally target a specific project.
No. The advisory states that all Aodh deployments are affected.
It can expose alarm metadata including webhook action URLs, signal endpoints, and project identifiers. Webhook URLs obtained this way may be usable against Watcher.
The attacker needs to be an authenticated user and know an audit's webhook URL. The endpoint does not apply authorization, so the user can start an EVENT audit and its associated action plan regardless of their own project.
Aodh is affected in versions >=10.0.0 and <20.0.1, and in versions 21.0.0 and 22.0.0. Watcher is affected in versions >=4.0.0 and <14.1.2, >=15.0.0 and <15.1.2, and >=16.0.0 and <16.0.2.