** Changed in: murano
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1464219
Title:
[api] there are no checks of request tenant_id during abandoning of an
environment
Status in murano:
Fix Released
Bug description:
Looks like the code currently does not check, that a given env belongs
to current requests tenant.
Therefore it might be possible for users from different tenants to
delete/deploy environments.
To manage notifications about this bug go to:
https://bugs.launchpad.net/murano/+bug/1464219/+subscriptions