In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
{
"binaries": [
{
"binary_version": "1:2.0.0-1",
"binary_name": "murano-api"
},
{
"binary_version": "1:2.0.0-1",
"binary_name": "murano-cfapi"
},
{
"binary_version": "1:2.0.0-1",
"binary_name": "murano-common"
},
{
"binary_version": "1:2.0.0-1",
"binary_name": "murano-engine"
},
{
"binary_version": "1:2.0.0-1",
"binary_name": "python-murano"
}
]
}
{
"binaries": [
{
"binary_version": "1:5.0.0-0ubuntu1",
"binary_name": "murano-api"
},
{
"binary_version": "1:5.0.0-0ubuntu1",
"binary_name": "murano-cfapi"
},
{
"binary_version": "1:5.0.0-0ubuntu1",
"binary_name": "murano-common"
},
{
"binary_version": "1:5.0.0-0ubuntu1",
"binary_name": "murano-engine"
},
{
"binary_version": "1:5.0.0-0ubuntu1",
"binary_name": "python-murano"
}
]
}
{
"binaries": [
{
"binary_version": "1:9.0.0-0ubuntu0.20.04.1",
"binary_name": "murano-api"
},
{
"binary_version": "1:9.0.0-0ubuntu0.20.04.1",
"binary_name": "murano-cfapi"
},
{
"binary_version": "1:9.0.0-0ubuntu0.20.04.1",
"binary_name": "murano-common"
},
{
"binary_version": "1:9.0.0-0ubuntu0.20.04.1",
"binary_name": "murano-engine"
},
{
"binary_version": "1:9.0.0-0ubuntu0.20.04.1",
"binary_name": "python3-murano"
}
]
}
{
"binaries": [
{
"binary_version": "1:13.0.0-0ubuntu1",
"binary_name": "murano-api"
},
{
"binary_version": "1:13.0.0-0ubuntu1",
"binary_name": "murano-cfapi"
},
{
"binary_version": "1:13.0.0-0ubuntu1",
"binary_name": "murano-common"
},
{
"binary_version": "1:13.0.0-0ubuntu1",
"binary_name": "murano-engine"
},
{
"binary_version": "1:13.0.0-0ubuntu1",
"binary_name": "python3-murano"
}
]
}
{
"binaries": [
{
"binary_version": "1:16.0.0-0ubuntu1",
"binary_name": "murano-api"
},
{
"binary_version": "1:16.0.0-0ubuntu1",
"binary_name": "murano-cfapi"
},
{
"binary_version": "1:16.0.0-0ubuntu1",
"binary_name": "murano-common"
},
{
"binary_version": "1:16.0.0-0ubuntu1",
"binary_name": "murano-engine"
},
{
"binary_version": "1:16.0.0-0ubuntu1",
"binary_name": "python3-murano"
}
]
}