CVE-2018-16849
Last modified
CVE-2018-16849 is a vulnerability of currently unknown severity. A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack-Mistral | < 7.0.1 |
References
- https://bugs.launchpad.net/mistral/+bug/1783708Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16849Issue Tracking, Vendor Advisory
- https://bugs.launchpad.net/mistral/+bug/1783708Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16849Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16849?
How severe is CVE-2018-16849?
How do I fix CVE-2018-16849?
Are you affected by CVE-2018-16849?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
