CVE-2018-16848
published 2020-06-15CVE-2018-16848: A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition…
PriorityP429medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.18%
64.0th percentile
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mistral | < mistral 10.0.0~rc1-2 (bookworm) | mistral 10.0.0~rc1-2 (bookworm) |
| redhat | openstack-mistral | <= 7.0.3 | — |
| redhat | openstack-mistral | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mistral, python-mistral-lib vulnerabilities
osv·2025-04-28·CVSS 6.5
CVE-2018-16848 [MEDIUM] mistral, python-mistral-lib vulnerabilities
mistral, python-mistral-lib vulnerabilities
It was discovered that Mistral incorrectly handled nested anchors in YAML
files. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848)
Pierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH
private key filename commands. An attacker could possibly use this issue to
expose sensitive information. (CVE-2018-16849)
It was discovered that Mistral incorrectly handled the permissions of
sensitive log files. An attacker could possibly use this issue to expose
sensitive information. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-3866)
OSV
OpenStack Mistral DoS
osv·2022-05-24
CVE-2018-16848 [HIGH] OpenStack Mistral DoS
OpenStack Mistral DoS
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
GHSA
OpenStack Mistral DoS
ghsa·2022-05-24
CVE-2018-16848 [HIGH] CWE-400 OpenStack Mistral DoS
OpenStack Mistral DoS
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
OSV
CVE-2018-16848: A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7
osv·2020-06-15·CVSS 6.5
CVE-2018-16848 [MEDIUM] CVE-2018-16848: A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
Ubuntu
Mistral vulnerabilities
vendor_ubuntu·2025-04-28·CVSS 6.5
CVE-2019-3866 [MEDIUM] Mistral vulnerabilities
Title: Mistral vulnerabilities
Summary: Several security issues were fixed in Mistral.
It was discovered that Mistral incorrectly handled nested anchors in YAML
files. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848)
Pierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH
private key filename commands. An attacker could possibly use this issue to
expose sensitive information. (CVE-2018-16849)
It was discovered that Mistral incorrectly handled the permissions of
sensitive log files. An attacker could possibly use this issue to expose
sensitive information. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-3866)
Instructions: In general, a standard system update will make all the neces
Red Hat
openstack-mistral: Potential Mistral Denial of Service handling recursive YAML anchor expansion
vendor_redhat·2020-06-10·CVSS 6.5
CVE-2018-16848 [MEDIUM] CWE-776 openstack-mistral: Potential Mistral Denial of Service handling recursive YAML anchor expansion
openstack-mistral: Potential Mistral Denial of Service handling recursive YAML anchor expansion
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
Package: openstack-mistral (Red Hat OpenStack Platform 10 (Newton)) - Will not fix
Package: openstack-mistral (Red Hat OpenStack Platform 12 (Pike)) - Out of support scope
P
Debian
CVE-2018-16848: mistral - A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions...
vendor_debian·2018·CVSS 6.5
CVE-2018-16848 [MEDIUM] CVE-2018-16848: mistral - A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions...
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
Scope: local
bookworm: resolved (fixed in 10.0.0~rc1-2)
bullseye: resolved (fixed in 10.0.0~rc1-2)
forky: resolved (fixed in 10.0.0~rc1-2)
sid: resolved (fixed in 10.0.0~rc1-2)
trixie: resolved (fixed in 10.0.0~rc1-2)
No detection rules found.
No public exploits indexed.
2020-06-15
Published