Back Linuxsecurity Debian 11: Mistral-Dashboard Critical Local File Inclusion DLA-4392
A local file inclusion vulnerability has been discovered in mistral- dashboard, the OpenStack Workflow as a Service dashboard plugin, that may result in disclosure of arbitrary local files content through the 'Create Workbook' feature. For Debian 11 bullseye, this problem has been fixed in version 11.0.0-2+deb11u1. We recommend that you upgrade your mistral-dashboard packages. For the detailed security status of mistral-dashboard please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
A local file inclusion vulnerability has been discovered in mistral- dashboard, the OpenStack Workflow as a Service dashboard plugin, that may result in disclosure of arbitrary local files content through the 'Create Workbook' feature. For Debian 11 bullseye, this problem has been fixed in version 11.0.0-2+deb11u1. We recommend that you upgrade your mistral-dashboard packages. For the detailed security status of mistral-dashboard please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
