[murano] YaqlYamlLoader inherits from YamlLoader
Bug #1593002 reported by
Kirill Zaitsev
This bug affects 1 person
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| Mirantis OpenStack |
Fix Released
|
Critical
|
Kirill Zaitsev | ||
| 5.1.x |
In Progress
|
Critical
|
MOS Maintenance | ||
| 6.0.x |
In Progress
|
Critical
|
MOS Maintenance | ||
| 6.1.x |
Fix Released
|
Critical
|
MOS Maintenance | ||
| 7.0.x |
Fix Released
|
Critical
|
MOS Maintenance | ||
| 8.0.x |
Fix Released
|
Critical
|
MOS Maintenance | ||
| 9.x |
Fix Released
|
Critical
|
Kirill Zaitsev | ||
Bug Description
YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://
dashboard, engine/api, and client are vulnerable.
CVE Description:
Kirill Zaitsev from Mirantis reported a vulnerability in OpenStack Murano applications processing. Using extended YAML tags in Murano application YAML files, an attacker can perform a Remote Code Execution attack.
CVE References
| tags: | added: feature-security |
| information type: | Private Security → Public Security |
| information type: | Public Security → Private Security |
| information type: | Private Security → Public Security |
| description: | updated |
To post a comment you must log in.
Setting to In Progress for 6.1-updates, 7.0-updates, 8.0-updates, the link to reviews is https:/ /review. fuel-infra. org/#/q/ topic:bug/ 1593002