In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano services MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Murano | Ubuntu | mantic | * |
Red Hat OpenStack Platform 16.2 | RedHat | openstack-tripleo-common-0:11.7.1-2.20230809225405.e189622.el8ost | * |
Red Hat OpenStack Platform 16.2 | RedHat | openstack-tripleo-heat-templates-0:11.6.1-2.20230808225220.el8ost | * |
Red Hat OpenStack Platform 16.2 | RedHat | python-yaql-0:1.1.3-9.el8ost | * |
Red Hat OpenStack Platform 17.1 for RHEL 8 | RedHat | openstack-tripleo-heat-templates-0:14.3.1-17.1.20231103003748.2.el8ost | * |
Red Hat OpenStack Platform 17.1 for RHEL 8 | RedHat | python-yaql-0:1.1.3-11.el8ost | * |
Red Hat OpenStack Platform 17.1 for RHEL 9 | RedHat | openstack-tripleo-heat-templates-0:14.3.1-17.1.20231103010826.2.el9ost | * |
Red Hat OpenStack Platform 17.1 for RHEL 9 | RedHat | python-yaql-0:1.1.3-11.el9ost | * |