Activity log for bug #1931558

Date Who What changed Old value New value Message
2021-06-10 10:03:42 Anh Nguyen bug added bug
2021-06-10 10:03:42 Anh Nguyen attachment added lfi-bug-workbook.zip https://bugs.launchpad.net/bugs/1931558/+attachment/5503832/+files/lfi-bug-workbook.zip
2021-06-10 10:05:33 Anh Nguyen description Hello, I've found a Local File Inclusion (LFI) vulnerability in creating a workbook on OpenStack Dashboard. This vulnerability allows the attacker to read a sensitive file on the server like /etc/password, config file, etc. Tested version: Victoria Horizon 18.6.3 I do not an opportunity to test the other version, but I think those versions also vulnerable. Steps to reproduce: 1. Create a text file datnt78.txt with content: "/etc/passwd" 2. Select Workflow -> Workbooks -> Create Workbook 3. In "Definition Source" select "File" then browse datnt78.txt file then click Validate and got /etc/passwd content. This is the request: http://paste.openstack.org/show/806520/ This is the response: http://paste.openstack.org/show/806521/ Please find the sample file and POC image in the attachment. Thank you, DatNT78 from FTEL CSOC Hello, I've found a Local File Inclusion (LFI) vulnerability in creating a workbook on OpenStack Dashboard. This vulnerability allows the attacker to read a sensitive file on the server like /etc/password, config file, etc. Tested version: Victoria Horizon 18.6.3 I do not an opportunity to test the other version, but I think those versions also vulnerable. Steps to reproduce: 1. Create a text file datnt78.txt with content: "/etc/passwd" 2. Select Workflow -> Workbooks -> Create Workbook 3. In "Definition Source" select "File" then browse datnt78.txt file then click Validate and got /etc/passwd content. This is the request: http://paste.openstack.org/show/806520/ This is the response: http://paste.openstack.org/show/806521/ Please find the sample file and POC image in the attachment. Thank you, DatNT78 at FTEL CSOC
2021-06-10 10:10:42 Anh Nguyen summary LFI vulnerability in creates a workbook LFI vulnerability in "Create Workbook"
2021-06-10 15:40:14 Akihiro Motoki horizon: status New Incomplete
2021-06-10 16:23:33 Anh Nguyen bug task added mistral
2021-06-10 18:08:13 Jeremy Stanley bug task added ossa
2021-06-10 18:08:24 Jeremy Stanley ossa: status New Won't Fix
2021-06-15 03:10:26 Anh Nguyen tags lfi lfi security
2021-06-15 05:33:09 Akihiro Motoki horizon: status Incomplete Invalid
2021-06-16 06:14:13 Anh Nguyen affects mistral python-mistralclient
2021-06-28 17:34:01 Jeremy Stanley bug added subscriber Adriano Petrich
2021-06-28 17:38:59 Adriano Petrich python-mistralclient: importance Undecided Critical
2021-07-02 16:37:27 Jeremy Stanley information type Private Security Public Security
2021-08-04 04:52:46 Akihiro Motoki bug task added mistral
2021-09-05 11:46:56 OpenStack Infra mistral: status New In Progress
2022-08-12 10:02:17 OpenStack Infra mistral: status In Progress Fix Released
2022-08-12 12:26:48 Takashi Kajinami python-mistralclient: status New Fix Released
2022-08-12 12:51:49 OpenStack Infra tags lfi security in-stable-yoga lfi security