- Package:
- src:watcher
- Source:
- src:watcher
- Submitter:
- Thomas Goirand
- Date:
- 2026-08-20 07:49:03 UTC
- Severity:
- normal
- Tags:
As per upstream announce at: https://security.openstack.org/ossa/OSSA-2026-036.html Date: August 19, 2026 CVE: CVE-2026-pending Affects: Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0 Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2 Description: Chen YuXiang of the Institute of Computing Technology, Chinese Academy of Sciences reported that OpenStack Aodh does not enforce project scope on the alarm listing API when the all_projects query parameter is supplied with a false value. A non-admin user holding only the reader role can list alarms belonging to other projects, optionally targeting a specific project, exposing alarm metadata such as webhook action URLs, signal endpoints, and project identifiers. All Aodh deployments are affected. The same reporter found that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit’s webhook URL, for example from the Aodh alarm metadata leaked above, can start an EVENT audit and its associated action plan regardless of their own project or role. All Watcher deployments are affected. Patches: https://review.opendev.org/1001503 (2025.1/epoxy (aodh)) https://review.opendev.org/1001509 (2025.1/epoxy (watcher)) https://review.opendev.org/1001502 (2025.2/flamingo (aodh)) https://review.opendev.org/1001508 (2025.2/flamingo (watcher)) https://review.opendev.org/1001501 (2026.1/gazpacho (aodh)) https://review.opendev.org/1001507 (2026.1/gazpacho (watcher)) https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh)) https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher)) Credits: Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences References: https://launchpad.net/bugs/2161276 https://launchpad.net/bugs/2161771 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending Notes: A CVE identifier was requested from MITRE for the aodh vulnerability on 2026-08-03. The CVE will be added to this advisory by errata once assigned.
Hello, Bug #1144880 in watcher reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/watcher/-/commit/dcbdf5acf728979c3e70a4609dd26acca6d6d62b ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not enforce oslo.policy authorization. Any authenticated user who learns a Watcher audit webhook URL can POST to the webhook to trigger an administrator-owned EVENT audit and its associated action plan, regardless of the caller's project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release. Applied upstream patch: "Add policy enforcement to webhook trigger endpoint". (Closes: #1144880) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144880
Hello, Bug #1144880 in watcher reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/watcher/-/commit/58877652150a4f55e2e88e4618df94da2f207e3f ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not enforce oslo.policy authorization. Any authenticated user who learns a Watcher audit webhook URL can POST to the webhook to trigger an administrator-owned EVENT audit and its associated action plan, regardless of the caller's project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release. Applied upstream patch: "Add policy enforcement to webhook trigger endpoint". (Closes: #1144880) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144880
Hello, Bug #1144880 in watcher reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/watcher/-/commit/eb7cb11a5cc3bc705e6c29844ee1fe193f73780d ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not enforce oslo.policy authorization. Any authenticated user who learns a Watcher audit webhook URL can POST to the webhook to trigger an administrator-owned EVENT audit and its associated action plan, regardless of the caller's project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release. Applied upstream patch: "Add policy enforcement to webhook trigger endpoint". (Closes: #1144880) * Added python3-ddt as build-depends, needed for this patch. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144880
Hello, Bug #1144880 in watcher reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/watcher/-/commit/9ed5bff13967ac096c3c548d1e865a6b0bbfe167 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not enforce oslo.policy authorization. Any authenticated user who learns a Watcher audit webhook URL can POST to the webhook to trigger an administrator-owned EVENT audit and its associated action plan, regardless of the caller's project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release. Applied upstream patch: "Add policy enforcement to webhook trigger endpoint". (Closes: #1144880) * Add python3-ddt as build-depends, needed for this patch. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144880
Hello, Bug #1144880 in watcher reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/watcher/-/commit/aa1a0808c309bd1d697c85b3b4e001fa09425b03 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not enforce oslo.policy authorization. Any authenticated user who learns a Watcher audit webhook URL can POST to the webhook to trigger an administrator-owned EVENT audit and its associated action plan, regardless of the caller's project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release. Applied upstream patch: "Add policy enforcement to webhook trigger endpoint". (Closes: #1144880) * Add python3-ddt as build-depends, needed for this patch. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144880
We believe that the bug you reported is fixed in the latest version of
watcher, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144880@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated watcher package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 10:12:23 +0200
Source: watcher
Architecture: source
Version: 16.0.0-5
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144880
Changes:
watcher (16.0.0-5) unstable; urgency=high
.
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
enforce oslo.policy authorization. Any authenticated user who learns a
Watcher audit webhook URL can POST to the webhook to trigger an
administrator-owned EVENT audit and its associated action plan, regardless
of the caller's project or role. The webhook endpoint has lacked policy
enforcement since its introduction in the Ussuri release. Applied upstream
patch: "Add policy enforcement to webhook trigger endpoint".
(Closes: #1144880)
Checksums-Sha1:
babfd42fa7d69d2e8e78b8d09a6b1ac5e634dbb3 3673 watcher_16.0.0-5.dsc
d503a26e19df3172959805da4b698cb749722cff 13604 watcher_16.0.0-5.debian.tar.xz
532cf284ac4a9383a4db997dd7acfac609fb9b07 18221 watcher_16.0.0-5_amd64.buildinfo
Checksums-Sha256:
6f9ae7c7e1d8b7ba0d1245411f1baa9934516c5efdaea495a0c445224c8542c5 3673 watcher_16.0.0-5.dsc
ebb90a6e83e0ded19ed088c2363cb701cbfb0d9c0b26eaa91d39bba877b83cbc 13604 watcher_16.0.0-5.debian.tar.xz
d0111b8457523022d6857effb03656eeb8c8639133be5a3d4f273e3add726c0a 18221 watcher_16.0.0-5_amd64.buildinfo
Files:
9a4450550f65f9600d7c4ffb390a4623 3673 net optional watcher_16.0.0-5.dsc
a0eef9198409b05b8de8adefcf5d4ce9 13604 net optional watcher_16.0.0-5.debian.tar.xz
4c4a6a09bb2750b3b592479f51e7f73d 18221 net optional watcher_16.0.0-5_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqGFTYACgkQ1BatFaxr
Q/6Yxw//aNw6kuFHNTUx1yePVdqjjPEegJv8WVJoFmjJqBJazrGRxOUN/ZySrwv3
FTWV8v/oJspaY/9z9EWnx4xXILLeJgY6luAx2HUTt7ZPG8HSi+51kceMrfU8WCTN
VtvW7VDC+mUmvTMupOY+2Rg5RWSSzDL6BoWQfEOfdmZCGsg8Nlr6hRCdvX3teF2W
2SShjU5Zgi9os1xTvJTOTKezLnXCnKI0Ixa6kF2DjQryKrZDcx8mwY7SSyhq3IZy
Siay+LoDbNGyPKhjziQBmpCAVylpvzgp672GTKxheYPUxwcVy9b8fX5P0UCy8/in
Uplqfptep5A8kyNO4zYiReEVCdgsCwo46sKUMSAp4MOrVmTzRIlVaajhFFTrRT4N
IzHKyURbb4zVZBhU+SmX6jCNpC0udqMUjGncRAyy/yWc8L0SUw7IJbkPsa10BTfb
aeu/nixrTgRbggcvCx5RUMuMWu/CRbTbYWmPmyBvaxqeu9If0rbnBnRZm6Rwn6B1
da2NJxJbkFzA9Z8A9Rq+KcNC2EOhc3uDI67xOtzbX9TMTYBgb/KWMXmqHVJZUg8a
wLYzKAQU26Fkbd3cvS2yl6h8NLhY0N89GYqbcJVEnecWoTObsvbQnb+HXyKrBnPu
rdvE42JiFS3RKn8wl6U8KBO9If9b+aWxE5SQgUmACKpw3q/B0Vk=
=Wh2/
-----END PGP SIGNATURE-----