Project

General

Profile

Actions

Bug #51206

closed

Creating a role in another tenant seems to be possible

Added by Daniel Iwan almost 3 years ago. Updated over 2 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Target version:
-
% Done:

0%

Source:
Tags:
sts role
Backport:
pacific octopus
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

This is a follow up for the thread on the mailing list
https://lists.ceph.io/hyperkitty/list/ceph-users@ceph.io/thread/5HWL3AV275Y5B4UMIEBMF34NDGDVABK4/

Using aws cli console (likely in other ways as well) it is possible to create a role in a tenant other than user's.
This can be done by prefixing role name with tenantName\$
The issue holds true both for the users authenticating with access keys and federated users who assume a role granting permissions to create roles.

This allows to obtain unauthorised cross-tenant access.
Reproduced on Ceph 16.2.1


Related issues 2 (0 open2 closed)

Copied to rgw - Backport #51778: octopus: Creating a role in another tenant seems to be possibleResolvedCory SnyderActions
Copied to rgw - Backport #51779: pacific: Creating a role in another tenant seems to be possibleResolvedCory SnyderActions
Actions #2

Updated by Pritha Srivastava almost 3 years ago

  • Status changed from New to Fix Under Review
  • Pull request ID set to 41858
Actions #3

Updated by Casey Bodley almost 3 years ago

  • Status changed from Fix Under Review to Pending Backport
  • Tags set to sts role
  • Backport set to pacific octopus
Actions #4

Updated by Backport Bot almost 3 years ago

  • Copied to Backport #51778: octopus: Creating a role in another tenant seems to be possible added
Actions #5

Updated by Backport Bot almost 3 years ago

  • Copied to Backport #51779: pacific: Creating a role in another tenant seems to be possible added
Actions #6

Updated by Loïc Dachary over 2 years ago

  • Status changed from Pending Backport to Resolved

While running with --resolve-parent, the script "backport-create-issue" noticed that all backports of this issue are in status "Resolved" or "Rejected".

Actions

Also available in: Atom PDF