In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
{
"binaries": [
{
"binary_name": "murano-api",
"binary_version": "1:2.0.0-1"
},
{
"binary_name": "murano-cfapi",
"binary_version": "1:2.0.0-1"
},
{
"binary_name": "murano-common",
"binary_version": "1:2.0.0-1"
},
{
"binary_name": "murano-engine",
"binary_version": "1:2.0.0-1"
},
{
"binary_name": "python-murano",
"binary_version": "1:2.0.0-1"
}
]
}
{
"binaries": [
{
"binary_name": "murano-api",
"binary_version": "1:5.0.0-0ubuntu1"
},
{
"binary_name": "murano-cfapi",
"binary_version": "1:5.0.0-0ubuntu1"
},
{
"binary_name": "murano-common",
"binary_version": "1:5.0.0-0ubuntu1"
},
{
"binary_name": "murano-engine",
"binary_version": "1:5.0.0-0ubuntu1"
},
{
"binary_name": "python-murano",
"binary_version": "1:5.0.0-0ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "murano-api",
"binary_version": "1:9.0.0-0ubuntu0.20.04.1"
},
{
"binary_name": "murano-cfapi",
"binary_version": "1:9.0.0-0ubuntu0.20.04.1"
},
{
"binary_name": "murano-common",
"binary_version": "1:9.0.0-0ubuntu0.20.04.1"
},
{
"binary_name": "murano-engine",
"binary_version": "1:9.0.0-0ubuntu0.20.04.1"
},
{
"binary_name": "python3-murano",
"binary_version": "1:9.0.0-0ubuntu0.20.04.1"
}
]
}
{
"binaries": [
{
"binary_name": "murano-api",
"binary_version": "1:13.0.0-0ubuntu1"
},
{
"binary_name": "murano-cfapi",
"binary_version": "1:13.0.0-0ubuntu1"
},
{
"binary_name": "murano-common",
"binary_version": "1:13.0.0-0ubuntu1"
},
{
"binary_name": "murano-engine",
"binary_version": "1:13.0.0-0ubuntu1"
},
{
"binary_name": "python3-murano",
"binary_version": "1:13.0.0-0ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "murano-api",
"binary_version": "1:16.0.0-0ubuntu1"
},
{
"binary_name": "murano-cfapi",
"binary_version": "1:16.0.0-0ubuntu1"
},
{
"binary_name": "murano-common",
"binary_version": "1:16.0.0-0ubuntu1"
},
{
"binary_name": "murano-engine",
"binary_version": "1:16.0.0-0ubuntu1"
},
{
"binary_name": "python3-murano",
"binary_version": "1:16.0.0-0ubuntu1"
}
]
}