VYPR
Moderate severityNVD Advisory· Published Mar 18, 2024· Updated Mar 25, 2025

CVE-2024-29156

CVE-2024-29156

Description

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
yaqlPyPI
< 3.0.03.0.0

Affected products

2
  • OpenStack/Muranodescription
  • ghsa-coords
    Range: < 3.0.0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.