Source: octavia
Version: 18.0.0-1
Severity: important
Tags: security upstream
Forwarded: https://bugs.launchpad.net/octavia/+bug/2161500
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for octavia.

CVE-2026-74248[0]:
| OpenStack Octavia through 18.0.0 mishandles quality of service (QoS)
| policy authorization. By associating another project's QoS policy
| with an amphora, an authenticated user may prevent deletion of that
| policy. All Octavia deployments are affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-74248
    https://www.cve.org/CVERecord?id=CVE-2026-74248
[1] https://www.openwall.com/lists/oss-security/2026/08/13/12
[2] https://bugs.launchpad.net/octavia/+bug/2161500

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to