CVE-2018-16849 Information

Description

A flaw was found in openstack-mistral. By manipulating the SSH private key filename the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path it can be used to assess whether or not a file exists on the executor’s filesystem.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://bugs.launchpad.net/mistral/+bug/1783708 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16849

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: