Impact
The vulnerability is in OpenStack Blazar’s V2 lease listing API. An authenticated user calling GET /v2/leases receives lease data for every project, because the request does not enforce project scoping or an administrator‑only policy. The exposed data includes lease IDs, reservation IDs, resource IDs, and reservation metadata, which together reveal sensitive scheduling information. The leaked lease IDs also satisfy a prerequisite for a later object‑level authorization bypass, letting an attacker modify or delete leases that belong to other tenants. This flaw therefore enables both information disclosure and potential tampering with resources across projects.
Affected Systems
All installations of OpenStack Blazar earlier than version 17.0.1 are affected. In particular, the reference update to 17.0.1 contains the fix for the lease listing path.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is below 1%, pointing to a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by authenticating to the Blazar REST API and issuing a simple GET request, which is typical for authenticated users. The lack of a policy check makes the attack trivial for any credentialed user. However, because the flaw also enables later modification via object‑level bypass, the combined impact is significant when used with the accompanying exploit.
OpenCVE Enrichment