PT-2018-13771 · Openstack+1 · Openstack-Mistral+1
CVE-2018-16849
·
Publicado
2018-11-02
·
Atualizado
2025-04-28
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openstack-mistral (affected versions not specified)
Description
A flaw in openstack-mistral allows the disclosure of the presence of arbitrary files within the filesystem of the executor running the action. This is achieved by manipulating the SSH private key filename in the std.ssh action, which can take an absolute path to assess whether a file exists on the executor's filesystem.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ubuntu
Openstack-Mistral