Return-Path: X-Original-To: apmail-cloudstack-issues-archive@www.apache.org Delivered-To: apmail-cloudstack-issues-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id E6B9010749 for ; Mon, 2 Dec 2013 07:07:45 +0000 (UTC) Received: (qmail 62487 invoked by uid 500); 2 Dec 2013 07:07:44 -0000 Delivered-To: apmail-cloudstack-issues-archive@cloudstack.apache.org Received: (qmail 62441 invoked by uid 500); 2 Dec 2013 07:07:44 -0000 Mailing-List: contact issues-help@cloudstack.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@cloudstack.apache.org Delivered-To: mailing list issues@cloudstack.apache.org Received: (qmail 62275 invoked by uid 500); 2 Dec 2013 07:07:44 -0000 Delivered-To: apmail-incubator-cloudstack-issues@incubator.apache.org Received: (qmail 62087 invoked by uid 99); 2 Dec 2013 07:07:39 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 02 Dec 2013 07:07:39 +0000 Date: Mon, 2 Dec 2013 07:07:38 +0000 (UTC) From: "Abhinandan Prateek (JIRA)" To: cloudstack-issues@incubator.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Updated] (CLOUDSTACK-5152) Basic Zone - Security group belonging to a project can be used to deploy VM outside the project (in same account, and also in different account) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/CLOUDSTACK-5152?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Abhinandan Prateek updated CLOUDSTACK-5152: ------------------------------------------- Assignee: Alena Prokharchyk > Basic Zone - Security group belonging to a project can be used to deploy VM outside the project (in same account, and also in different account) > ------------------------------------------------------------------------------------------------------------------------------------------------ > > Key: CLOUDSTACK-5152 > URL: https://issues.apache.org/jira/browse/CLOUDSTACK-5152 > Project: CloudStack > Issue Type: Bug > Security Level: Public(Anyone can view this level - this is the default.) > Components: Network Controller > Affects Versions: 4.3.0 > Reporter: Gaurav Aradhye > Assignee: Alena Prokharchyk > Fix For: 4.3.0 > > > In basic zone, > Create an account and a project in that account. > Create a security group which belongs to this project. > Try to deploy VM using this security group outside the project. > Creation of VM is successful and if you list the virtual machines, in response it will show the security group in the sec groups list and it will show the account of security group as the account in which you have deployed the instance (instead it should list the project to which security group belongs) > This is an issue, security group belonging to a project should not be allowed to be used outside the project. -- This message was sent by Atlassian JIRA (v6.1#6144)