Описание
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.
An information-disclosure flaw was discovered in openstack-mistral, where the SSH private key filename of a std.ssh action could be manipulated. The flaw could be exploited to determine the presence of a file path on the host executing the std.ssh action, based on the returned error message.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 14 (Rocky) | openstack-mistral | Out of support scope | ||
| Red Hat OpenStack Platform 15 (Stein) | openstack-mistral | Affected | ||
| Red Hat OpenStack Platform 13.0 (Queens) | instack-undercloud | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-mistral | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-common | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-heat-templates | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-image-elements | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-puppet-elements | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-ui | Fixed | RHBA-2019:0448 | 14.03.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-validations | Fixed | RHBA-2019:0448 | 14.03.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.
A flaw was found in openstack-mistral. By manipulating the SSH private ...
openstack-mistral Discloses the presence of arbitrary files within the filesystem
EPSS
4.3 Medium
CVSS3