USN-8422-1: Mistral vulnerability
摘要
Mistral could be made to expose sensitive information or run code.
正文
Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that Mistral did not properly enforce access policies on some API endpoints. An attacker could possibly execute arbitrary code on a Mistral worker and possibly extract sensitive data including service credentials from it.
标签
- release:jammy
- release:noble
- release:questing
- release:resolute
- USN
扩展字段
{
"cve_ids": [
"CVE-2026-41283"
],
"guid": "https://ubuntu.com/security/notices/USN-8422-1",
"instructions": "In general, a standard system update will make all the necessary changes.",
"raw_pub_date": "Thu, 11 Jun 2026 12:55:21 +0000",
"release_packages": {
"jammy": [
{
"description": "OpenStack Workflow Service",
"is_source": true,
"name": "mistral",
"version": "14.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-api",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "14.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-common",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "14.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "14.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-event-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "14.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-executor",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "14.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "python3-mistral",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "14.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubuntu1.1"
}
],
"noble": [
{
"description": "OpenStack Workflow Service",
"is_source": true,
"name": "mistral",
"version": "18.0.1-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-api",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "18.0.1-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-common",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "18.0.1-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "18.0.1-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-event-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "18.0.1-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-executor",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "18.0.1-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "python3-mistral",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "18.0.1-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubuntu1.1"
}
],
"questing": [
{
"description": "OpenStack Workflow Service",
"is_source": true,
"name": "mistral",
"version": "21.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-api",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "21.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-common",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "21.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "21.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-event-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "21.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-executor",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "21.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "python3-mistral",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "21.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubuntu1.1"
}
],
"resolute": [
{
"description": "OpenStack Workflow Service",
"is_source": true,
"name": "mistral",
"version": "22.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-api",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "22.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-common",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "22.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "22.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-event-engine",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "22.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "mistral-executor",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "22.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1"
},
{
"is_source": false,
"is_visible": true,
"name": "python3-mistral",
"pocket": "security",
"source_link": "https://launchpad.net/ubuntu/+source/mistral",
"version": "22.0.0-0ubuntu1.1",
"version_link": "https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubuntu1.1"
}
]
},
"releases": [
{
"codename": "resolute",
"support_tag": "LTS",
"version": "26.04"
},
{
"codename": "questing",
"support_tag": "",
"version": "25.10"
},
{
"codename": "noble",
"support_tag": "LTS",
"version": "24.04"
},
{
"codename": "jammy",
"support_tag": "LTS",
"version": "22.04"
}
]
}