{"id":"UBUNTU-CVE-2021-4472","details":"The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.","modified":"2026-05-20T16:05:20.683020749Z","published":"2025-11-26T19:15:00Z","upstream":["CVE-2021-4472"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-4472"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-4472"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2021-4472"},{"type":"REPORT","url":"https://bugs.launchpad.net/horizon/+bug/1931558"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2417321"},{"type":"REPORT","url":"https://review.opendev.org/c/openstack/mistral-dashboard/+/800952"},{"type":"REPORT","url":"https://review.opendev.org/c/openstack/python-mistralclient/+/800950"}],"affected":[{"package":{"name":"mistral-dashboard","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/mistral-dashboard?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.1-2","9.0.0-1","9.0.0-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-mistral-dashboard","binary_version":"9.0.0-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4472.json"}},{"package":{"name":"mistral-dashboard","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/mistral-dashboard?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["11.0.0-2","13.0.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"13.0.0-1","binary_name":"python3-mistral-dashboard"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4472.json"}},{"package":{"name":"mistral-dashboard","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/mistral-dashboard?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["16.0.0-4","17.0.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"17.0.0-1","binary_name":"python3-mistral-dashboard"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4472.json"}},{"package":{"name":"mistral-dashboard","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/mistral-dashboard?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20.0.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"20.0.0-0ubuntu1","binary_name":"python3-mistral-dashboard"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4472.json"}},{"package":{"name":"mistral-dashboard","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/mistral-dashboard?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20.0.0-0ubuntu1","20.0.0-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"20.0.0-0ubuntu2","binary_name":"python3-mistral-dashboard"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4472.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}