Skip to content

Get All Access Info Of a Cluster Kubernetes Through API Key's User #7618

@VanDuy91

Description

@VanDuy91
ISSUE TYPE
  • Bug Report
COMPONENT NAME
API, Kubernetes
CLOUDSTACK VERSION
4.18.0.0
CONFIGURATION
  • Apply role to the user: User role(default role on Cloustack)
  • Generate keys for the user
OS / ENVIRONMENT

Ubuntu 22.04

SUMMARY

Any user can get access info of a cluster from another one if they have the ID of the cluster

STEPS TO REPRODUCE
- Set role to a user: Default User role on Cloudstack
- Generate keys for the user
- Get access  info of  a cluster from another user (e.g. xxx is the ID cluster of user A, but user B can get info of xxx cluster through API of user B (B has the ID cluster of A) )
EXPECTED RESULTS
Can't get info of a cluster Kubernetes if they not own
ACTUAL RESULTS
Get all of info of a cluster if we have ID of any cluster

Metadata

Metadata

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions