cbcvebase.

Debian Mistral vulnerabilities

4 known vulnerabilities affecting debian/mistral.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-41283P2CRITICAL≥ 20.0.0, < 20.1.12026-06-04
CVE-2026-41283 [CRITICAL] CWE-749 OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
ghsa
CVE-2018-16849P3LOWCVSS 3.1fixed in mistral 7.0.0-2 (bookworm)2018
CVE-2018-16849 [LOW] CVE-2018-16849: mistral - A flaw was found in openstack-mistral. By manipulating the SSH private key filen... A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem. Scope
debian
CVE-2018-16848P4MEDIUMCVSS 6.5fixed in mistral 10.0.0~rc1-2 (bookworm)2018
CVE-2018-16848 [MEDIUM] CVE-2018-16848: mistral - A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions... A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service. Scope: local bookworm: resolved (fixed in 10.0.0~rc1-2) bullseye: resolved (fixed in 10.0.0~rc1-2) fork
debian
CVE-2019-3866P4MEDIUMCVSS 5.5fixed in mistral 5.1.0-2 (bookworm)2019
CVE-2019-3866 [MEDIUM] CVE-2019-3866: mistral - An information-exposure vulnerability was discovered where openstack-mistral's u... An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information. Scope: local bookworm: resolved (fixed in 5.1.0-2) bullseye: resolved (fixed in 5.1.0-2) forky: resolved (fixed in 5.1.0-2
debian
Debian Mistral vulnerabilities | cvebase