CVE Vulnerabilities

CVE-2024-29156

Published: Mar 18, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.4 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano services MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

Affected Software

Name Vendor Start Version End Version
Red Hat OpenStack Platform 16.2 RedHat openstack-tripleo-common-0:11.7.1-2.20230809225405.e189622.el8ost *
Red Hat OpenStack Platform 16.2 RedHat openstack-tripleo-heat-templates-0:11.6.1-2.20230808225220.el8ost *
Red Hat OpenStack Platform 16.2 RedHat python-yaql-0:1.1.3-9.el8ost *
Red Hat OpenStack Platform 17.1 for RHEL 8 RedHat openstack-tripleo-heat-templates-0:14.3.1-17.1.20231103003748.2.el8ost *
Red Hat OpenStack Platform 17.1 for RHEL 8 RedHat python-yaql-0:1.1.3-11.el8ost *
Red Hat OpenStack Platform 17.1 for RHEL 9 RedHat openstack-tripleo-heat-templates-0:14.3.1-17.1.20231103010826.2.el9ost *
Red Hat OpenStack Platform 17.1 for RHEL 9 RedHat python-yaql-0:1.1.3-11.el9ost *
Murano Ubuntu mantic *

References