| Name | CVE-2021-4472 |
| Description | The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-4391-1, DLA-4392-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| mistral-dashboard (PTS) | bullseye | 11.0.0-2 | vulnerable |
| bullseye (security) | 11.0.0-2+deb11u1 | fixed |
| bookworm | 15.0.0-2 | fixed |
| trixie | 20.0.0-1 | fixed |
| forky, sid | 21.0.0-1 | fixed |
| python-mistralclient (PTS) | bullseye | 1:4.1.1-2 | vulnerable |
| bullseye (security) | 1:4.1.1-2+deb11u1 | fixed |
| bookworm | 1:4.5.0-2 | fixed |
| trixie | 1:5.4.0-2 | fixed |
| forky, sid | 1:6.0.0-2 | fixed |
The information below is based on the following data on fixed versions.
Notes
https://review.opendev.org/c/openstack/mistral-dashboard/+/800952
Fixed by: https://opendev.org/openstack/mistral-dashboard/commit/8b876b0b22b365f24af1eb9eae01ad3d22cc1533 (15.0.0.0rc1)
Fixed by: https://opendev.org/openstack/mistral-dashboard/commit/c077728bfa6001f0cb1ac22b0bacd74eb1967b04 (14.0.1)
https://review.opendev.org/c/openstack/python-mistralclient/+/800950
Fixed by: https://opendev.org/openstack/python-mistralclient/commit/ab54cb9ae576c2b29c7cd9a9628f3908aaa3e0ee (4.3.0)