CVE-2018-16849
Summary
| CVE | CVE-2018-16849 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-02 21:29:00 UTC |
| Updated | 2019-10-09 23:36:00 UTC |
| Description | A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Openstack-mistral | All | All | All | All |
| Application | Redhat | Openstack-mistral | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1783708 “std.ssh action can be used to explore executor's f...” : Bugs : Mistral | CONFIRM | bugs.launchpad.net | Third Party Advisory |
| 1645334 – (CVE-2018-16849) CVE-2018-16849 openstack-mistral: std.ssh action may disclose presence of arbitrary files | CONFIRM | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.