Re: HELP with CLOUDSTACK-5145 security issue

2013-11-26 Thread Marcus Sorensen
che.org>" > mailto:dev@cloudstack.apache.org>> > Subject: HELP with CLOUDSTACK-5145 security issue > > Is there anyone who can help with CLOUDSTACK-5145? There's a security > issue with 4.2+ due to the new ACL design. Anyone listing ACLs sees > ALL ACLs in

Re: HELP with CLOUDSTACK-5145 security issue

2013-11-26 Thread Alena Prokharchyk
> Date: Tuesday, November 26, 2013 8:28 AM To: "dev@cloudstack.apache.org<mailto:dev@cloudstack.apache.org>" mailto:dev@cloudstack.apache.org>> Subject: HELP with CLOUDSTACK-5145 security issue Is there anyone who can help with CLOUDSTACK-5145? There's a security is

HELP with CLOUDSTACK-5145 security issue

2013-11-26 Thread Marcus Sorensen
Is there anyone who can help with CLOUDSTACK-5145? There's a security issue with 4.2+ due to the new ACL design. Anyone listing ACLs sees ALL ACLs in the system, and if a network has no ACLs then filtering by network also lists ALL ACLs. As you can imagine, this causes a lot of problems. I could