#1144989 trixie-pu: package aodh/20.0.0-2

#1144989#5
Date:
2026-08-21 07:49:04 UTC
From:
To:
Hi,

[ Reason ]
I'd like to upload aodh 20.0.0-2+deb13u1, in order to address:
https://security.openstack.org/ossa/OSSA-2026-036.html
aka:
https://bugs.debian.org/1144879

[ Impact ]
As per upstream announce:
Aodh does not enforce project scope on the
alarm listing API when the all_projects query parameter is supplied with a
false value. A non-admin user holding only the reader role can list alarms
belonging to other projects, optionally targeting a specific project, exposing
alarm metadata such as webhook action URLs, signal endpoints, and project
identifiers.

[ Tests ]
I've run OpenStack functional testing on my CI, and Aodh appeared to
continue working. On top of this, the patch includes new tests. I've
also deployed the patched version in production in our public cloud.

[ Risks ]
Minimum: well tested, and small patch.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Please allow me to upload aodh/20.0.0-2+deb13u1 to p-u.

Cheers,

Thomas Goirand (zigo)

#1144989#12
Date:
2026-08-21 12:08:20 UTC
From:
To:
hi,

This is CVE-2026-76878, can you please expand the changelog to note
it?

Regards,
Salvatore

#1144989#17
Date:
2026-08-21 13:23:31 UTC
From:
To:
One other thing, this does not look it is fixed in unstable yet? Did
the upload maybe failed/got interruped?

Regards,
Salvatore