← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1304320] Re: neutron port-update takes unavailable and invalid device-ids

 

** Information type changed from Private Security to Public

** Changed in: ossa
       Status: Incomplete => Invalid

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1304320

Title:
  neutron port-update takes unavailable and invalid device-ids

Status in OpenStack Neutron (virtual network service):
  Invalid
Status in OpenStack Security Advisories:
  Invalid

Bug description:
  TenantA can port-update device-ids belonging to tenantB or even other
  tenants

  $neutron port-update <port-id-tenant-A> --device_owner=compute:az1 --device_id=<unavailable_invalid device_id of tenantB>
  Updated port: <port-id-tenant-A>

  Expected Behavior: tenant should not be able to update unavailable or
  invalid device-ids using neutron port-update.

To manage notifications about this bug go to:
https://bugs.launchpad.net/neutron/+bug/1304320/+subscriptions