Debian Package Tracker
Register | Log in
Subscribe

aodh

Choose email to subscribe with

general
  • source: aodh (main)
  • version: 22.0.0-2
  • maintainer: Debian OpenStack (DMD)
  • uploaders: Thomas Goirand [DMD] – Michal Arbet [DMD]
  • arch: all
  • std-ver: 4.4.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 11.0.0-2
  • oldstable: 15.0.0-3
  • stable: 20.0.0-2
  • testing: 22.0.0-2
  • unstable: 22.0.0-2
versioned links
  • 11.0.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 15.0.0-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20.0.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 22.0.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • aodh-api
  • aodh-common
  • aodh-doc
  • aodh-evaluator
  • aodh-expirer
  • aodh-listener
  • aodh-notifier
  • python3-aodh
action needed
Marked for autoremoval on 05 September due to httpcore, ipywidgets, node-playwright, node-vscode-lsp, node-yarnpkg, python-repoze.who, towncrier: #1135849, #1138720, #1141793, #1143321, #1143428, #1143694, #1144575, #1144608 high
Version 22.0.0-2 of aodh is marked for autoremoval from testing on Sat 05 Sep 2026. It depends (transitively) on httpcore, ipywidgets, node-playwright, node-vscode-lsp, node-yarnpkg, python-repoze.who, towncrier, affected by #1135849, #1138720, #1141793, #1143321, #1143428, #1143694, #1144575, #1144608. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-01 Last update: 2026-08-24 03:04
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-76878: In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
Created: 2026-08-20 Last update: 2026-08-20 21:20
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-76878: In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
Created: 2026-08-20 Last update: 2026-08-20 21:20
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-76878: In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
Created: 2026-08-20 Last update: 2026-08-20 21:20
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-76878: In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
Created: 2026-08-20 Last update: 2026-08-20 21:20
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 22.0.0-3, distribution unstable) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit f75635916b4a82ef228e26a55be12a6110ef6520
Author: Thomas Goirand <zigo@debian.org>
Date:   Wed Aug 12 09:55:17 2026 +0200

      * CVE-2026-76878 / OSSA-2026-03X: Aodh does not correctly enforce project
        scope when the all_projects query parameter is present with a false value.
        A non-admin project reader can list alarms belonging to other projects by
        passing all_projects=false in a list query, optionally combined with a
        foreign project_id to target a specific project. Leaked alarm data includes
        trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
        upstream patch: "Fix all_projects=false bypass project scope"
        (Closes: #1144879).


https://salsa.debian.org/api/v4/projects/openstack-team%2Fservices%2Faodh API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-08-19 Last update: 2026-08-21 13:31
lintian reports 23 warnings normal
Lintian reports 23 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-06-02 Last update: 2026-06-02 07:30
debian/patches: 3 patches to forward upstream low

Among the 4 debian patches available in version 22.0.0-2 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-02 08:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.4.1).
Created: 2020-01-21 Last update: 2026-06-02 01:30
news
[rss feed]
  • [2026-06-07] aodh 22.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-01] Accepted aodh 22.0.0-2 (source) into unstable (Thomas Goirand)
  • [2026-04-03] aodh 22.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-01] Accepted aodh 22.0.0-1 (source) into unstable (Thomas Goirand)
  • [2026-03-31] aodh 22.0.0~rc1-5 MIGRATED to testing (Debian testing watch)
  • [2026-03-27] Accepted aodh 22.0.0~rc1-5 (source) into unstable (Thomas Goirand)
  • [2026-03-18] Accepted aodh 22.0.0~rc1-4 (source) into experimental (Thomas Goirand)
  • [2026-03-18] Accepted aodh 22.0.0~rc1-3 (source) into experimental (Thomas Goirand)
  • [2026-03-11] Accepted aodh 22.0.0~rc1-2 (source) into experimental (Thomas Goirand)
  • [2026-03-11] Accepted aodh 22.0.0~rc1-1 (source) into experimental (Thomas Goirand)
  • [2025-12-09] aodh 21.0.0-4 MIGRATED to testing (Debian testing watch)
  • [2025-12-07] Accepted aodh 21.0.0-4 (source) into unstable (Thomas Goirand)
  • [2025-11-28] aodh 21.0.0-3 MIGRATED to testing (Debian testing watch)
  • [2025-11-26] Accepted aodh 21.0.0-3 (source) into unstable (Thomas Goirand)
  • [2025-10-04] aodh 21.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-01] Accepted aodh 21.0.0-2 (source) into unstable (Thomas Goirand)
  • [2025-10-01] Accepted aodh 21.0.0-1 (source) into unstable (Thomas Goirand)
  • [2025-10-01] aodh 21.0.0~rc1-2 MIGRATED to testing (Debian testing watch)
  • [2025-09-28] Accepted aodh 21.0.0~rc1-2 (source) into unstable (Thomas Goirand)
  • [2025-09-15] Accepted aodh 21.0.0~rc1-1 (source) into experimental (Thomas Goirand)
  • [2025-07-18] aodh 20.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-07-11] Accepted aodh 20.0.0-2 (source) into unstable (Thomas Goirand)
  • [2025-04-05] aodh 20.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-02] Accepted aodh 20.0.0-1 (source) into unstable (Thomas Goirand)
  • [2025-04-01] Accepted aodh 20.0.0~rc1-3 (source) into unstable (Thomas Goirand)
  • [2025-03-31] aodh 20.0.0~rc1-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-28] Accepted aodh 20.0.0~rc1-2 (source) into unstable (Thomas Goirand)
  • [2025-03-20] Accepted aodh 20.0.0~rc1-1 (source) into experimental (Thomas Goirand)
  • [2024-12-22] aodh 19.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2024-12-20] Accepted aodh 19.0.0-2 (source) into unstable (Thomas Goirand)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 0
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (0, 23)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 99)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:22.0.0-0ubuntu1
  • patches for 1:22.0.0-0ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing