CVE-2024-29156

MEDIUM

OpenStack Murano <16.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 45.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (3)
openstack/murano < 16.0.0
openstack/yaql < 3.0.0
pypi/yaql 0 - 3.0.0PyPI
Published Mar 18, 2024
Tracked Since Feb 18, 2026