CVE-2024-29156

Source
https://cve.org/CVERecord?id=CVE-2024-29156
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-29156.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-29156
Aliases
Downstream
DEBIAN (1)
OESA (5)
RHSA (3)
UBUNTU (1)
Published
2024-03-18T00:00:00Z
Modified
2026-07-07T17:57:01Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29156.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "16.0.0"
                },
                {
                    "fixed":  "3.0.0"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/openstack-archive/murano

Affected ranges

Type
GIT
Repo
https://github.com/openstack-archive/murano
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:openstack:yaql:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.0.0"
        }
    ],
    "source":  "CPE_FIELD"
}

Affected versions

1.*
1.0.0
1.0.0.0b1
1.0.0.0b2
1.0.0.0b3
1.0.0.0rc1
1.0.0.0rc2
1.0.0a0
2.*
2.0.0.0b1
2.0.0.0b2
2.0.0.0b3
2.0.0.0rc1
2014.*
2014.2.b1
2014.2.b2
2014.2.b3
2014.2.rc1
2014.2.rc2
2015.*
2015.1.0b1
2015.1.0b2
2015.1.0b3
2015.1.0rc1
3.*
3.0.0.0b1
3.0.0.0b2
3.0.0.0b3
3.0.0.0rc1
Other
i4
iteration3-code-freeze

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-29156.json"