PT-2018-13771 · Openstack+1 · Openstack-Mistral+1

CVE-2018-16849

·

Publicado

2018-11-02

·

Atualizado

2025-04-28

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openstack-mistral (affected versions not specified)
Description A flaw in openstack-mistral allows the disclosure of the presence of arbitrary files within the filesystem of the executor running the action. This is achieved by manipulating the SSH private key filename in the std.ssh action, which can take an absolute path to assess whether a file exists on the executor's filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16849
GHSA-FQW7-C6VR-Q29M
PYSEC-2018-92
USN-7465-1

Produtos afetados

Ubuntu
Openstack-Mistral