UNKNOWN OpenStack
CVE-2017-12440
OSSN-0080: = Aodh can be used to launder Keystone trusts =
When adding an alarm action with the scheme `trust+http:` Aodh does not
verify that the user creating the alarm is the trustor or has the same
rights as the trustor, nor that the trust is for the same project as the
alarm.
Affected Products
- CVE-2017-12440
References
This unknown severity vulnerability was published on 2026-08-27 via OpenStack. Affected: CVE-2017-12440.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.