[OSSN-0109] Cross-project metric association bypass in Gnocchi
OpenStack Gnocchi lets authenticated users attach metrics to other projects' resources, bypassing authorization checks.
OpenStack Security Note OSSN-0109, posted by Goutham Pacha Ravi on 7 October 2026, describes an authorization flaw in Gnocchi. The metric creation endpoint accepts a resource_id and associates the new metric with that resource without checking that the caller owns it. Authenticated users can therefore link metrics to resources belonging to other projects. The note does not cite a CVE or report in-the-wild exploitation.
- OSSN-0109 describes a cross-project authorization bypass in Gnocchi.
- Metric creation accepts resource_id without verifying resource ownership.
- Authenticated users can attach metrics to other projects' resources.
- The note cites no CVE and does not report active exploitation.
Posted by Goutham Pacha Ravi on Oct 07 ========================================================================== OSSN-0109: Cross-project metric association bypass in Gnocchi (2026-10-07) ========================================================================== Summary ~~~~~~~ The Gnocchi metric creation endpoint allows authenticated users to associate metrics with resources owned by others by passing resource_id in the request body bypassing proper authorization checks. This...
This source does not provide full text. Read it at seclists.org.