The dialog for creating cloud volumes (cinder provider)...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 20, 2023
Description
Published by the National Vulnerability Database
Jul 27, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 20, 2023
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
References