Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. mistral
  4. ›
  5. CVE-2018-16849

CVE-2018-16849: openstack-mistral Discloses the presence of arbitrary files within the filesystem

May 13, 2022 (updated September 24, 2024)

A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor’s filesystem.

References

  • bugs.launchpad.net/mistral/+bug/1783708
  • bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16849
  • github.com/advisories/GHSA-fqw7-c6vr-q29m
  • github.com/openstack/mistral
  • github.com/openstack/mistral/commit/2309e5265a1d5f28480ae872817b5de05f66e83c
  • github.com/openstack/mistral/commit/c93b45a61f49d4633f76d8e117cd89063e7759c4
  • github.com/pypa/advisory-database/tree/main/vulns/mistral/PYSEC-2018-92.yaml
  • nvd.nist.gov/vuln/detail/CVE-2018-16849

Code Behaviors & Features

Detect and mitigate CVE-2018-16849 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 7.0.1

Fixed versions

  • 7.0.1

Solution

Upgrade to version 7.0.1 or above.

Impact 7.5 HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Source file

pypi/mistral/CVE-2018-16849.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:53 +0000.