CVE Vulnerabilities

CVE-2024-29156

Published: Mar 18, 2024 | Modified: Mar 25, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.4 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano services MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

Affected Software

NameVendorStart VersionEnd Version
MuranoOpenstack*16.0.0 (including)
YaqlOpenstack*3.0.0 (excluding)
Red Hat OpenStack Platform 16.2RedHatopenstack-tripleo-common-0:11.7.1-2.20230809225405.e189622.el8ost*
Red Hat OpenStack Platform 16.2RedHatopenstack-tripleo-heat-templates-0:11.6.1-2.20230808225220.el8ost*
Red Hat OpenStack Platform 16.2RedHatpython-yaql-0:1.1.3-9.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatopenstack-tripleo-heat-templates-0:14.3.1-17.1.20231103003748.2.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatpython-yaql-0:1.1.3-11.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatrhel8/python-yaql:0:1.1.3-11.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatrhel9/python-yaql:0:1.1.3-11.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatopenstack-tripleo-heat-templates-0:14.3.1-17.1.20231103010826.2.el9ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatpython-yaql-0:1.1.3-11.el9ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatrhel8/python-yaql:0:1.1.3-11.el9ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatrhel9/python-yaql:0:1.1.3-11.el9ost*
MuranoUbuntufocal*
MuranoUbuntumantic*
MuranoUbuntuoracular*

References