CVE-2016-4972

CRITICAL

Openstack Mitaka-murano < 2.0.0 - Improper Input Validation

Title source: rule

Description

OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows remote attackers to create arbitrary Python objects and execute arbitrary code via crafted extended YAML tags in UI definitions in packages.

Scores

CVSS v3 9.8
EPSS 0.0393
EPSS Percentile 88.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-20
Status draft

Affected Products (7)

openstack/mitaka-murano < 2.0.0
openstack/murano < 1.0.2
openstack/murano-dashboard < 1.0.2
openstack/python-muranoclient < 0.7.2
pypi/murano < 1.0.3PyPI
pypi/murano-dashboard < 1.0.3PyPI
pypi/python-muranoclient < 0.7.3PyPI

Timeline

Published Sep 26, 2016
Tracked Since Feb 18, 2026