PT-2018-13771 · Openstack+1 · Openstack-Mistral+1
Published
2018-11-02
·
Updated
2025-04-28
·
CVE-2018-16849
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openstack-mistral (affected versions not specified)
Description
A flaw in openstack-mistral allows the disclosure of the presence of arbitrary files within the filesystem of the executor running the action. This is achieved by manipulating the SSH private key filename in the std.ssh action, which can take an absolute path to assess whether a file exists on the executor's filesystem.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu
Openstack-Mistral