Impact
In OpenStack Blazar prior to version 17.0.1, the v2 lease API does not enforce object‑level authorization on its update (PUT /v2/leases/{lease_id}) and delete (DELETE /v2/leases/{lease_id}) operations. The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword "lease_id" whereas the controller methods name the parameter "id" (and the wsme_pecan.wsexpose wrapper delivers it positionally). The lookup returns None, and thus authorization falls back to the requesting user’s own project_id/user_id instead of the lease owner, allowing any authenticated user who knows a lease ID to modify or delete leases belonging to other users and projects, bypassing the intended ownership check.
Affected Systems
OpenStack Blazar, all releases before 17.0.1.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact vulnerability; the EPSS score of < 1% implies a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated API request to PUT or DELETE a lease using a known lease identifier. The vulnerability requires the attacker to be authenticated against the Blazar service and to know a valid lease ID, after which the attacker can alter lease attributes or remove the lease entirely, bypassing ownership checks.
OpenCVE Enrichment