I can associate IP addresses to other users instances
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Invalid
|
Undecided
|
Unassigned |
Bug Description
Hi,
I'm using ubuntu 10.10 with nova installed from trunk: version 2012.1-dev (2012.1-
I have created a new user tom, added them to an existing project called project2 and given them sysadmin role in the project.
As tom I can allocated myself an address (in this case 131.227.75.52)
root@cloud-
ADDRESS 131.227.75.50 None (project1)
ADDRESS 131.227.75.51 i-00000243 (project2)
ADDRESS 131.227.75.52 i-00000250 (project2)
As you can see its in project2
But I can now associate it to an instance started by another user in another project:
euca-associate-
INSTANCE i-00000250 ami-00000003 131.227.75.52 10.0.0.15 running None (project1, compute03) 1 m1.small 2011-10-
I have also noticed that just creating a user and then adding to a project (without adding any roles) allows them to describe all images (euca-describe-
Regards John
Needs to be assessed by vuln-mgmt