UbuntuUpdates.org

Package "mistral"

Name: mistral

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • OpenStack Workflow service - API
  • OpenStack Workflow service - common files
  • OpenStack Workflow service - Engine
  • OpenStack Workflow service - Event Engine

Latest version: 21.0.0-0ubuntu1.1
Release: questing (25.10)
Level: security
Repository: universe

Links



Other versions of "mistral" in Questing

Repository Area Version
base universe 21.0.0-0ubuntu1
updates universe 21.0.0-0ubuntu1.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 21.0.0-0ubuntu1.1 2026-06-11 15:07:37 UTC

  mistral (21.0.0-0ubuntu1.1) questing-security; urgency=high

  [ Myles Penner ]
  * d/gbp.conf: Create stable/2025.2 branch.
  * d/gbp.conf, .launchpad.yaml: Sync from cloud-archive-tools for
    flamingo.

  [ Ubuntu Developers ]
  * SECURITY UPDATE: overly permissive publicize policies allow non-admin
    users to make resources public
    - d/p/cve-2026-41283-restrict-publicize-policies-admin-only.patch:
      Restrict publicize policies to admin only for actions, workflows,
      and event triggers.
    - d/p/cve-2026-41283-remove-expect-errors-policy-tests.patch:
      Update policy tests to remove expect_errors from admin-only calls.
    - d/p/cve-2026-41283-add-code-sources-publicize-policy.patch:
      Add publicize policy for code sources resource.
    - d/p/cve-2026-41283-restrict-code-sources-dynamic-actions.patch:
      Restrict code sources and dynamic actions to admin only.
    - d/p/cve-2026-41283-add-dynamic-actions-publicize-policy.patch:
      Add publicize policy for dynamic actions resource.
    - d/p/cve-2026-41283-add-workbooks-publicize-policy.patch:
      Add publicize policy for workbooks resource.
    - d/p/cve-2026-41283-add-cron-triggers-publicize-policy.patch:
      Add publicize policy for cron triggers resource.
    - d/p/cve-2026-41283-add-environments-publicize-policy.patch:
      Add publicize policy for environments resource.
    - CVE-2026-41283

 -- Hemanth Nakkina <email address hidden> Sun, 31 May 2026 13:01:30 +0530

CVE-2026-41283 OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which



About   -   Send Feedback to @ubuntu_updates