Your message dated Tue, 28 Jul 2026 16:34:59 +0000
with message-id <[email protected]>
and subject line Bug#1138849: fixed in mistral 22.0.0-3
has caused the Debian Bug report #1138849,
regarding OSSN-0098: Mistral workflow execution context exposes Keystone auth 
token
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1138849: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138849
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mistral
Version: 22.0.0-1
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

OSSN-0098: Mistral workflow execution context exposes Keystone auth token

== Summary ==

Eduardo Gonzalez Gutierrez reported that Mistral stores the Keystone
authentication token in the workflow execution context. Any user who
can create or inspect workflow executions can retrieve active tokens
via YAQL or Jinja2 expressions and use them to perform actions as the
workflow initiator. Deployments where untrusted users can create or
execute workflows are affected.

== Affected Services / Software ==

* mistral: <=22.0.0

== Discussion ==

When a workflow execution starts, Mistral copies the full Keystone
authentication context into the execution's stored context. This
includes the auth_token and service_catalog. The fix masks these
fields and is only applied to the master branch. Backporting to stable
branches would break workflows that rely on the
$.openstack.auth_token context variable.

== Recommended Actions ==

Operators running stable branches of Mistral should:

* Restrict who can create and inspect workflow executions using
  Mistral's policy configuration.
* Audit workflow definitions for references to
  $.openstack.auth_token.
* Upgrade to the next major release of Mistral when available, which
  will include the fix.

The fix masks auth_token and service_catalog in the workflow execution
context. It is applied to the master branch only.

* 2026.2/hibiscus (master):
  [https://review.opendev.org/c/openstack/mistral/+/991391 Gerrit
  991391]

== Credits ==

Eduardo Gonzalez Gutierrez (Independent)
Arnaud Morin, OVHCloud

== Contacts / References ==

* Authors: Goutham Pacha Ravi, Red Hat
* This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0098
* Original Launchpad bug: https://launchpad.net/bugs/2146554
* Mailing List: [security-sig] tag on [email protected]
* OpenStack Security: https://security.openstack.org/
* CVE: none 

--- End Message ---
--- Begin Message ---
Source: mistral
Source-Version: 22.0.0-3
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
mistral, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated mistral package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 04 Jun 2026 23:56:19 +0200
Source: mistral
Architecture: source
Version: 22.0.0-3
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1138849
Changes:
 mistral (22.0.0-3) unstable; urgency=medium
 .
   * OSSN-0098: Mistral workflow execution context exposes Keystone auth token.
     Applied upstream patch: "Strip sensitive info from workflow execution
     context" (Closes: #1138849).
Checksums-Sha1:
 1ef913b469fb9ef5af1b10eaadb3bd497bf49eb0 3446 mistral_22.0.0-3.dsc
 e949a7ff91fa47da51efa8f0ce97097cd63aceea 22132 mistral_22.0.0-3.debian.tar.xz
 898d1168fe579ae1f8484c7674b4266f70edd57b 16819 mistral_22.0.0-3_amd64.buildinfo
Checksums-Sha256:
 09dd4a902255d799e63812e6735dd261d4830eaa68a66a9a3bf1c3ae3b61949a 3446 
mistral_22.0.0-3.dsc
 ecefb039db3562fe1da790625c3faf21ddb8cb0863453e389d661b3e07b00728 22132 
mistral_22.0.0-3.debian.tar.xz
 7088005ca97645ba582f12c92c55c94a96701529761ace5a2b312e00a17e2b34 16819 
mistral_22.0.0-3_amd64.buildinfo
Files:
 545d72cce09ca30d4b2bf4c64976174c 3446 net optional mistral_22.0.0-3.dsc
 b33385a5a31985d0a0348624c2b4b6dc 22132 net optional 
mistral_22.0.0-3.debian.tar.xz
 c95316829373c6537be3e4c808a2841f 16819 net optional 
mistral_22.0.0-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmpo1TYACgkQ1BatFaxr
Q/54Qg/+JImeAiXeGaPbDSVofLUB5TV5U7JHQN8eQnx/pHytIBUoH+xZggt6qvV4
O/WTsOLQ1Mdw8a/S+PqL4x0iiMbNjXHj32MxccZFXUfrM8kZ2N6VVPjgT1JtAjjo
kWsWnpOeGPsYq+xqlx2BSPvp1thDWG9AOUS5o+srhzLMfTefsVswX27zog1UFHox
jmf3+jEul9iH2lG1wmaBK83L/D/hiPAVmEHjpw2QYVWxBEkkFew0gXv0egQWt230
KuiOs0HOWZM9F1YWcAD41un0BWywb9ovnb1is0J+3xLI4gGKkz8PQfHlYV2m5h2J
DZxRm5SMDgCL7zk5btgdo8Fh5dCpWgCVb5BhOXIcdfAs0RRe/q5fIruImT+FeLXd
eQK4xbuEUTgtOfryjyOOoLEZaPsxK2cNRbIgGxrtfqkU0uDc2YgYDPlbbHNdEYco
CVBoI71mAU3iZn4bYTmRGM410z63WBaMRL5U7Sig2aWWDKZW1/XVi5ZVbA8QgwOs
nogKzhMP88UM83m+PeP/pmOkt75nFWdPfwqcXNDmlAyhHyfKUbwoANB/kSts+Qw2
rP8v6MLU7CGECjPq3AYsaKWGlUkVRIRC3qcBdYBb0SOUjKwZ51SiuYmt26l87d+P
yfqFfzrPI090JcWbo9lFnuy9/FKjA5YwW5CfFj8GNhG0pRjwP2U=
=LCB4
-----END PGP SIGNATURE-----

Attachment: pgphIai1erl6G.pgp
Description: PGP signature


--- End Message ---

Reply via email to