ISSUE TYPE
COMPONENT NAME
CLOUDSTACK VERSION
CONFIGURATION
N/A
OS / ENVIRONMENT
Ubuntu 22.04
KVM
SUMMARY
We found that out of the box listSystemVmsUsageHistory is available to the Domain Admin Role with Type set to DomainAdmin by default. This feels like a bug since no other SystemVM API's are available. We worked around this issue by denying the API, however, I wanted to report it.
STEPS TO REPRODUCE
Create an account/user with the Domain Admin Role and set the Type to DomainAdmin. Run listSystemVmsUsageHistory
EXPECTED RESULTS
listSystemVmsUsageHistory should not be available
ACTUAL RESULTS
listSystemVmsUsageHistory returns results
ISSUE TYPE
COMPONENT NAME
CLOUDSTACK VERSION
CONFIGURATION
N/A
OS / ENVIRONMENT
Ubuntu 22.04
KVM
SUMMARY
We found that out of the box listSystemVmsUsageHistory is available to the Domain Admin Role with Type set to DomainAdmin by default. This feels like a bug since no other SystemVM API's are available. We worked around this issue by denying the API, however, I wanted to report it.
STEPS TO REPRODUCE
EXPECTED RESULTS
ACTUAL RESULTS