<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:52:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-68401</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-68401</link>
      <description>EUVD-2026-68401</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-68401</guid>
    </item>
    <item>
      <title>fkie_cve-2018-16849</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-16849</link>
      <description>&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-16849</guid>
    </item>
    <item>
      <title>GHSA-fqw7-c6vr-q29m — openstack-mistral Discloses the presence of arbitrary files within the filesystem</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fqw7-c6vr-q29m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mistral&lt;/p&gt;
&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mistral&lt;/p&gt;
&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fqw7-c6vr-q29m</guid>
    </item>
    <item>
      <title>gsd-2018-16849</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-16849</link>
      <description>gsd-2018-16849</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-16849</guid>
    </item>
    <item>
      <title>PYSEC-2018-92</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2018-92</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mistral&lt;/p&gt;
&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mistral&lt;/p&gt;
&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2018-92</guid>
    </item>
    <item>
      <title>RHBA-2019:0448 — Red Hat Bug Fix Advisory: Red Hat OpenStack Platform 13.0 director Bug Fix Advisory</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2019:0448</link>
      <description>&lt;p&gt;openstack-mistral: std.ssh action may disclose presence of arbitrary files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openstack-mistral: std.ssh action may disclose presence of arbitrary files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2019:0448</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-16849</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-16849</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: mistral, Ubuntu:Pro:18.04:LTS: mistral&lt;/p&gt;
&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: mistral, Ubuntu:Pro:18.04:LTS: mistral&lt;/p&gt;
&lt;p&gt;A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor&amp;#39;s filesystem.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-16849</guid>
    </item>
  </channel>
</rss>
