UbuntuUpdates.org

Package "mistral-api"

Name: mistral-api

Description:

OpenStack Workflow service - API

Latest version: 22.0.0-0ubuntu1.1
Release: resolute (26.04)
Level: security
Repository: universe
Head package: mistral
Homepage: https://opendev.org/openstack/mistral

Links


Download "mistral-api"


Other versions of "mistral-api" in Resolute

Repository Area Version
base universe 22.0.0-0ubuntu1
updates universe 22.0.0-0ubuntu1.1

Changelog

Version: 22.0.0-0ubuntu1.1 2026-06-11 15:07:37 UTC

  mistral (22.0.0-0ubuntu1.1) resolute-security; urgency=high

  [ Myles Penner ]
  * d/gbp.conf: Create stable/2026.1 branch.

  [ Hemanth Nakkina ]
  * SECURITY UPDATE: unauthorized resource publication via overly permissive
    publicize policies in workflows, actions, event triggers, code sources,
    dynamic actions, workbooks, cron triggers, and environments.
    - d/p/cve-2026-41283-restrict-publicize-policies-admin-only.patch:
      restrict publicize policies to admin_only for workflows, actions and
      event triggers; add missing enforcement on event trigger update.
    - d/p/cve-2026-41283-remove-expect-errors-policy-tests.patch:
      clean up unnecessary expect_errors=True in policy tests.
    - d/p/cve-2026-41283-add-code-sources-publicize-policy.patch:
      add code_sources:publicize policy (admin_only) and enforce on
      create/update.
    - d/p/cve-2026-41283-restrict-code-sources-dynamic-actions.patch:
      restrict code_sources and dynamic_actions operations to admin_only.
    - d/p/cve-2026-41283-add-dynamic-actions-publicize-policy.patch:
      add dynamic_actions:publicize policy (admin_only) and enforce on
      create/update.
    - d/p/cve-2026-41283-add-workbooks-publicize-policy.patch:
      add workbooks:publicize policy (admin_only) and enforce on
      create/update.
    - d/p/cve-2026-41283-add-cron-triggers-publicize-policy.patch:
      add cron_triggers:publicize policy (admin_only) and enforce on create.
    - d/p/cve-2026-41283-add-environments-publicize-policy.patch:
      add environments:publicize policy (admin_only) and enforce on
      create/update.
    - CVE-2026-41283

 -- Hemanth Nakkina <email address hidden> Sun, 01 Jun 2026 06:00:00 +0000

CVE-2026-41283 OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which



About   -   Send Feedback to @ubuntu_updates