Back Linuxsecurity Debian 11: python-mistralclient Important Local File Inclusion DLA-4391
A local file inclusion vulnerability has been discovered in python- mistralclient, the OpenStack Workflow as a Service client, that may result in disclosure of arbitrary local files content through the 'Create Workbook' feature. For Debian 11 bullseye, this problem has been fixed in version 1:4.1.1-2+deb11u1. We recommend that you upgrade your python-mistralclient packages. For the detailed security status of python-mistralclient please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
A local file inclusion vulnerability has been discovered in python- mistralclient, the OpenStack Workflow as a Service client, that may result in disclosure of arbitrary local files content through the 'Create Workbook' feature. For Debian 11 bullseye, this problem has been fixed in version 1:4.1.1-2+deb11u1. We recommend that you upgrade your python-mistralclient packages. For the detailed security status of python-mistralclient please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
