Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hfw-w3f4-c4p8

Опубликовано: 04 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.9

Описание

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Пакеты

Наименование

mistral

pip
Затронутые версииВерсия исправления

>= 20.0.0, < 20.1.1

20.1.1

Наименование

mistral

pip
Затронутые версииВерсия исправления

= 21.0.0

Отсутствует

Наименование

mistral

pip
Затронутые версииВерсия исправления

= 22.0.0

Отсутствует

EPSS

Процентиль: 51%
0.00733
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-749
CWE-863

Связанные уязвимости

CVSS3: 9.9
ubuntu
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

CVSS3: 9.9
redhat
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

CVSS3: 9.9
nvd
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

CVSS3: 9.9
debian
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Executio ...

EPSS

Процентиль: 51%
0.00733
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-749
CWE-863