-
Epic
-
Resolution: Done-Errata
-
Critical
-
None
-
None
-
CVE-2023-2088-support
-
False
-
-
False
-
OSPRH-811Red Hat OpenStack 18.0 Greenfield Deployment
-
Committed
-
No Docs Impact
-
To Do
-
OSPRH-811 - Red Hat OpenStack 18.0 Greenfield Deployment
-
nova-operator-container-1.0.0-14 cinder-operator-container-1.0.0-12
-
Committed
-
No impact
-
0% To Do, 0% In Progress, 100% Done
-
Release Note Not Required
-
Automated
-
-
-
2024Q1
-
Approved
https://bugs.launchpad.net/nova/+bug/2004555
As part of resolving CVE-2023-2088 there are a number of deployment tool modifications that are required to close the CVE.
This involves always generating the service_user config in Nova (and ideally in all services that support it)
adapting the service user creation to apply the the service role to the service users e.g. nova, neutron ectra.
enabling service_token role checking
configuring multipath to verify the the roles on the service token and assert the service role is present.
in the context of the CVE this epic applies to all service that interact with the cinder attachments API but in general these changes should be applied to all OpenStack service operators.