This bug was fixed in the package cinder - 2:22.0.0-0ubuntu4
--------------- cinder (2:22.0.0-0ubuntu4) mantic; urgency=medium
* SECURITY UPDATE: Unauthorized File Access (LP: #2021980) - debian/patches/CVE-2023-2088-1.patch: Reject unsafe delete attachment calls. - debian/patches/CVE-2023-2088-2.patch: Doc: Improve service token. - CVE-2023-2088
-- Corey Bryant <email address hidden> Fri, 26 May 2023 16:16:03 -0400
This bug was fixed in the package cinder - 2:22.0.0-0ubuntu4
---------------
cinder (2:22.0.0-0ubuntu4) mantic; urgency=medium
* SECURITY UPDATE: Unauthorized File Access (LP: #2021980) patches/ CVE-2023- 2088-1. patch: Reject unsafe delete patches/ CVE-2023- 2088-2. patch: Doc: Improve service token.
- debian/
attachment calls.
- debian/
- CVE-2023-2088
-- Corey Bryant <email address hidden> Fri, 26 May 2023 16:16:03 -0400