OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows remote attackers to create arbitrary Python objects and execute arbitrary code via crafted extended YAML tags in UI definitions in packages.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2016-09-26T16:00:00
Updated: 2024-08-06T00:46:40.056Z
Reserved: 2016-05-24T00:00:00
Link: CVE-2016-4972
Vulnrichment
No data.
NVD
Status : Modified
Published: 2016-09-26T16:59:01.210
Modified: 2024-11-21T02:53:20.270
Link: CVE-2016-4972
Redhat