aodh@4.0.3 vulnerabilities

OpenStack Telemetry Alarming

Direct Vulnerabilities

Known vulnerabilities in the aodh package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Missing Authentication for Critical Function

aodh is an OpenStack Telemetry Alarming

Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the alarm action creation process. An attacker can obtain a Keystone token and perform authenticated actions by adding an alarm action with the scheme trust+http and providing a trust ID where Aodh is the trustee.

How to fix Missing Authentication for Critical Function?

Upgrade aodh to version 6.0.1 or higher.

[,6.0.1)