Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4472

Опубликовано: 26 нояб. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

Отчет

The vulnerability is present at the mistral-dashboard which is not shipped by any Red Hat products. The mistral-dashboard insecurely uses a feature of the python-mistralclient component which is not intended to be used at the server side.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-aodh-apiFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-aodh-baseFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-aodh-evaluatorFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-aodh-listenerFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-aodh-notifierFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-barbican-apiFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-barbican-baseFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-barbican-keystone-listenerFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-barbican-workerFix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-ceilometer-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=2417321python-mistralclient: mistral-dashboard: Local file inclusion through the 'Create Workbook' feature

EPSS

Процентиль: 38%
0.00461
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
9 месяцев назад

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

CVSS3: 6.5
nvd
9 месяцев назад

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

CVSS3: 6.5
debian
9 месяцев назад

The mistral-dashboard plugin for openstack has a local file inclusion ...

CVSS3: 6.5
github
9 месяцев назад

OpenStack's Mistral Client has a local file inclusion vulnerability

EPSS

Процентиль: 38%
0.00461
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2021-4472