Title: Nova Filter Scheduler bypass through rebuild action
Reporter: George Shuklin (servers.com)
Products: Nova
Affects: >=13.0.0 <=13.1.3, >=14.0.0 <=14.0.4, ==15.0.0
Description:
George Shuklin from servers.com reported a vulnerability in Nova.
By rebuilding a malicious instance, an authenticated user may be able to bypass
Filter Scheduler resulting in restrictions violation such as the
ImagePropertiesFilter and the IsolatedHostsFilter. All setups using Nova
Filter Scheduler are affected.
This looks like a class A type of bug according to VMT's taxonomy ( https:/ /security. openstack. org/vmt- process. html#incident- report- taxonomy ), though I'm in favor for fixing this in the open since the impact sounds limited.
Impact description draft:
Title: Nova Filter Scheduler bypass through rebuild action
Reporter: George Shuklin (servers.com)
Products: Nova
Affects: >=13.0.0 <=13.1.3, >=14.0.0 <=14.0.4, ==15.0.0
Description: Filter and the IsolatedHostsFi lter. All setups using Nova
George Shuklin from servers.com reported a vulnerability in Nova.
By rebuilding a malicious instance, an authenticated user may be able to bypass
Filter Scheduler resulting in restrictions violation such as the
ImageProperties
Filter Scheduler are affected.