cbcvebase.
CVE-2018-16849
published 2018-11-02

CVE-2018-16849: A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files…

PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.52%
71.7th percentile
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianmistral< mistral 7.0.0-2 (bookworm)mistral 7.0.0-2 (bookworm)
redhatopenstack-mistral< 7.0.17.0.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.