VulnerabilityModified
CVE-2024-29156
In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
MEDIUM 6.5EPSS 0.75%
Does this matter?
Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.
Description
In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116
- Affected
- openstack/murano · openstack/yaql
- Source
- cve@mitre.org
References
- https://launchpad.net/bugs/2048114Issue Tracking, Third Party Advisory
- https://opendev.org/openstack/murano/tagsIssue Tracking
- https://opendev.org/openstack/yaql/commit/83e28324e1a0ce3970dd854393d2431123a909d3Patch
- https://wiki.openstack.org/wiki/OSSN/OSSN-0093Product
- https://launchpad.net/bugs/2048114Issue Tracking, Third Party Advisory
- https://opendev.org/openstack/murano/tagsIssue Tracking
- https://opendev.org/openstack/yaql/commit/83e28324e1a0ce3970dd854393d2431123a909d3Patch
- https://wiki.openstack.org/wiki/OSSN/OSSN-0093Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.