在 OpenStack Mistral 23.0.0 及更早版本中,其 v2 API 的多个写入路径存在漏洞。这些路径在解析目标对象时使用了一种查询方式,该查询可能返回属于其他项目的资源,随后对其进行写入操作。已认证的项目成员可利用此漏洞,重写并取消发布其他项目的公开操作定义和环境配置。此外,项目管理员可以创建工作簿,其中嵌入的临时操作或工作流的名称与另一个项目中的资源发生名称冲突,从而导致该资源被转移到调用者所在的项目中,并使得原始拥有者在后续对该资源进行更新时引发服务器错误。只有公开暴露 Mistral API
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93858 | 8.7 HIGH | OpenStack Mistral≤23.0.0远程命令执行漏洞 |
| CVE-2026-93860 | 7.1 HIGH | OpenStack Mistral≤23.0.0 API越权致服务中断 |
| CVE-2026-93861 | 6.0 MEDIUM | OpenStack Mistral通过API实现越权访问 |
No comments yet