CVE-2024-29156

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:murano:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:yaql:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-03-18 07:15

Updated : 2025-03-25 20:15


NVD link : CVE-2024-29156

Mitre link : CVE-2024-29156

CVE.ORG link : CVE-2024-29156


JSON object : View

Products Affected

openstack

  • murano
  • yaql
CWE
NVD-CWE-noinfo CWE-116

Improper Encoding or Escaping of Output