CVE-2019-3866
published 2019-11-08CVE-2019-3866: An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.34%
26.0th percentile
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mistral | < mistral 5.1.0-2 (bookworm) | mistral 5.1.0-2 (bookworm) |
| debian | python-mistral-lib | < mistral 5.1.0-2 (bookworm) | mistral 5.1.0-2 (bookworm) |
| debian | python-oslo.utils | < mistral 5.1.0-2 (bookworm) | mistral 5.1.0-2 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mistral vulnerabilities
vendor_ubuntu·2025-04-28·CVSS 6.5
CVE-2019-3866 [MEDIUM] Mistral vulnerabilities
Title: Mistral vulnerabilities
Summary: Several security issues were fixed in Mistral.
It was discovered that Mistral incorrectly handled nested anchors in YAML
files. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848)
Pierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH
private key filename commands. An attacker could possibly use this issue to
expose sensitive information. (CVE-2018-16849)
It was discovered that Mistral incorrectly handled the permissions of
sensitive log files. An attacker could possibly use this issue to expose
sensitive information. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-3866)
Instructions: In general, a standard system update will make all the neces
Red Hat
openstack-mistral: information disclosure in mistral log
vendor_redhat·2019-11-07·CVSS 5.5
CVE-2019-3866 [MEDIUM] CWE-732 openstack-mistral: information disclosure in mistral log
openstack-mistral: information disclosure in mistral log
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
Statement: In Red Hat OpenStack Platform 10/13, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP10/13 openstack-mistral package.
Mitigation: Pl
Debian
CVE-2019-3866: mistral - An information-exposure vulnerability was discovered where openstack-mistral's u...
vendor_debian·2019·CVSS 5.5
CVE-2019-3866 [MEDIUM] CVE-2019-3866: mistral - An information-exposure vulnerability was discovered where openstack-mistral's u...
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
Scope: local
bookworm: resolved (fixed in 5.1.0-2)
bullseye: resolved (fixed in 5.1.0-2)
forky: resolved (fixed in 5.1.0-2)
sid: resolved (fixed in 5.1.0-2)
trixie: resolved (fixed in 5.1.0-2)
OSV
mistral, python-mistral-lib vulnerabilities
osv·2025-04-28·CVSS 6.5
CVE-2018-16848 [MEDIUM] mistral, python-mistral-lib vulnerabilities
mistral, python-mistral-lib vulnerabilities
It was discovered that Mistral incorrectly handled nested anchors in YAML
files. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848)
Pierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH
private key filename commands. An attacker could possibly use this issue to
expose sensitive information. (CVE-2018-16849)
It was discovered that Mistral incorrectly handled the permissions of
sensitive log files. An attacker could possibly use this issue to expose
sensitive information. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-3866)
GHSA
GHSA-237x-6c63-mfj6: An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world
ghsa_unreviewed·2022-05-24
CVE-2019-3866 [LOW] CWE-732 GHSA-237x-6c63-mfj6: An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
OSV
CVE-2019-3866: An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world
osv·2019-11-08·CVSS 5.5
CVE-2019-3866 [MEDIUM] CVE-2019-3866: An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3866 openstack-mistral-3: openstack-mistral: information disclosure in mistral log [openstack-rdo]
bugzilla·2019-11-07·CVSS 5.5
CVE-2019-3866 [MEDIUM] CVE-2019-3866 openstack-mistral-3: openstack-mistral: information disclosure in mistral log [openstack-rdo]
CVE-2019-3866 openstack-mistral-3: openstack-mistral: information disclosure in mistral log [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
So thi
Bugzilla
CVE-2019-3866 openstack-mistral: information disclosure in mistral log
bugzilla·2019-11-05·CVSS 5.5
CVE-2019-3866 [MEDIUM] CVE-2019-3866 openstack-mistral: information disclosure in mistral log
CVE-2019-3866 openstack-mistral: information disclosure in mistral log
A vulnerability was discovered that all the data from the TripleO heat stack (user provided and generated passwords, certificates, ssh keys) are available in the mistral logs on the undercloud, in clear text.
Discussion:
Created openstack-mistral-3 tracking bugs for this issue:
Affects: openstack-rdo [bug 1770043]
---
Upstream bug: https://bugs.launchpad.net/tripleo/+bug/1850843
Patch for Pike and newer: https://launchpadlibrarian.net/449472809/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch
---
Acknowledgments:
Name: the OpenStack project
Upstream: Gauvain Pocentek and Clément Beaufils (Kindred Group PLC)
---
Patch for Ocata and older: https://launchpadlibrarian.net/449473654/0001-Ensure-we-m
2019-11-08
Published