UNKNOWN OpenStack

CVE-2017-12440

OSSN-0080: = Aodh can be used to launder Keystone trusts =

When adding an alarm action with the scheme `trust+http:` Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm.

Affected Products

References

Published: 2026-08-27 · Source: OpenStack · Feed updated: 2026-08-27
This unknown severity vulnerability was published on 2026-08-27 via OpenStack. Affected: CVE-2017-12440.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.