Comment 21 for bug 1069904

Revision history for this message
Thierry Carrez (ttx) wrote : Re: No authentication on block device used for os-volume_boot

@rmk: any progress on the Essex patch ?

Adding the full Diablo maintenance team (rather than just Dave) to evaluate Diablo's vulnerability, although having the Essex patch will help in assessing that.

My proposed impact description:

Title: Boot from volume allows access to random volumes
Reporter: Phil Day (HP)
Products: Nova
Affects: ??

Description:
Phil Day from HP reported a vulnerability in volume attachment in nova-volume, affecting the boot-from-volume feature. By passing a specific volume ID, an authenticated user may be able to boot from a volume he doesn't own, potentially resulting in full access to that 3rd-party volume contents. Folsom setups making use of Cinder are not affected.