Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Essex | Openstack | * | * |
Nova | Openstack | 2011.3 (including) | 2011.3 (including) |
Nova | Ubuntu | devel | * |
Nova | Ubuntu | oneiric | * |