Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-29156
HistoryMar 18, 2024 - 12:00 a.m.

CVE-2024-29156

2024-03-1800:00:00
ubuntu.com
ubuntu.com
8
openstack
murano
yaql
sensitive data

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the
Murano service’s MuranoPL extension to the YAQL language fails to sanitize
the supplied environment, leading to potential leakage of sensitive service
account information.

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%