PT-2018-13771 · Openstack+1 · Openstack-Mistral+1

Published

2018-11-02

·

Updated

2025-04-28

·

CVE-2018-16849

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openstack-mistral (affected versions not specified)
Description A flaw in openstack-mistral allows the disclosure of the presence of arbitrary files within the filesystem of the executor running the action. This is achieved by manipulating the SSH private key filename in the std.ssh action, which can take an absolute path to assess whether a file exists on the executor's filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2018-16849
GHSA-FQW7-C6VR-Q29M
PYSEC-2018-92
USN-7465-1

Affected Products

Ubuntu
Openstack-Mistral