Impact
The vulnerability in OpenStack Zaqar allows an authenticated user with a valid Keystone token for one project to substitute another project's UUID in WebSocket requests. This oversight permits enumeration, inspection, creation, or deletion of queues belonging to a different project, thereby exposing, tampering with, or deleting queue data. The weakness stems from improper validation of the project identifier in subsequent WebSocket requests, identified as CWE‑472.
Affected Systems
OpenStack Zaqar deployments using the WebSocket transport with Keystone authentication, prior to version 23.0.1, are affected. The issue is confined to environments where WebSocket transport is enabled and Keystone token authentication is in use.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating a moderate impact. Its EPSS score is not available, and it is not listed in CISA’s KEV catalog, suggesting limited commercial exploitation so far. An attacker requiring an authenticated Keystone token for one project can exploit the flaw by forging a different project’s UUID in WebSocket requests, potentially from a remote location. The attack requires network connectivity to the Zaqar WebSocket endpoint and knowledge of target project identifiers.
OpenCVE Enrichment