First published: Fri Nov 02 2018(Updated: )
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack-mistral | <=7.0.3 | |
pip/mistral | <10.0.0 | 10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-16848 is medium, with a severity value of 6.5.
To fix the vulnerability CVE-2018-16848, you should update OpenStack Mistral to version 7.0.4 or higher.
Versions up to and including 7.0.3 of OpenStack Mistral are affected by CVE-2018-16848.
Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.
You can find more information about CVE-2018-16848 in the following references: [1] [2] [3].