There is 1 open security issue in sid.
There is 1 open security issue in forky.
There is 1 open security issue in bullseye.
There is 1 open security issue in bookworm.
commit f75635916b4a82ef228e26a55be12a6110ef6520
Author: Thomas Goirand <zigo@debian.org>
Date: Wed Aug 12 09:55:17 2026 +0200
* CVE-2026-76878 / OSSA-2026-03X: Aodh does not correctly enforce project
scope when the all_projects query parameter is present with a false value.
A non-admin project reader can list alarms belonging to other projects by
passing all_projects=false in a list query, optionally combined with a
foreign project_id to target a specific project. Leaked alarm data includes
trust webhook URLs, Heat signal endpoints, and project identifiers. Applied
upstream patch: "Fix all_projects=false bypass project scope"
(Closes: #1144879).
Among the 4 debian patches available in version 22.0.0-2 of the package, we noticed the following issues: