在 OpenStack Mistral 23.0.0 及之前版本中, API 控制器会清除请求上下文,并直接调用维护服务,而未实施任何策略权限控制。因此,任何持有有效 Mistral 令牌的用户,无论其被授予何种角色,都可以读取和更改该服务的集群级维护状态。将此状态设置为 PAUSED(暂停)后,所有租户项目中的新工作流和执行对象都将停止处理,直到操作员将其恢复为止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93858 | 8.7 HIGH | OpenStack Mistral≤23.0.0远程命令执行漏洞 |
| CVE-2026-97147 | 7.2 HIGH | OpenStack Mistral 23.0.0越权修改/接管项目资源漏洞 |
| CVE-2026-93861 | 6.0 MEDIUM | OpenStack Mistral通过API实现越权访问 |
No comments yet