Back

HIGH

openstack-mistral: std.ssh action may disclose presence of arbitrary files

Published Nov 2, 2018

Description

A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (6)
  1. MITRE
    • CVSS severity changed from MEDIUM to LOW
    • CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N to CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
    • CVSS score changed from 4.3 to 3.1
  2. REDHAT
    • CVSS severity changed from LOW to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N to CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
    • CVSS score changed from 3.1 to 4.3
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 2, 2018
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 2, 2018
GHSA-FQW7-C6VR-Q29M