Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in OpenStack Mistral. Several of Mistral's v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can exploit this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, moving that resource into the caller's project and causing the original owner's subsequent updates to fail with server errors. All deployments exposing the Mistral API are affected. Affected versions: <20.1.1, ==21.0.0, ==22.0.0, ==23.0.0 Reference: https://launchpad.net/bugs/2160267