In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
History

Tue, 25 Mar 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack murano
Openstack yaql
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:openstack:murano:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:yaql:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack murano
Openstack yaql

Tue, 25 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-116
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-25T20:07:53.472Z

Reserved: 2024-03-18T00:00:00.000Z

Link: CVE-2024-29156

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:53.909Z

cve-icon NVD

Status : Modified

Published: 2024-03-18T07:15:05.880

Modified: 2025-03-25T20:15:21.533

Link: CVE-2024-29156

cve-icon Redhat

Severity : Important

Publid Date: 2024-03-14T00:00:00Z

Links: CVE-2024-29156 - Bugzilla