Skip to content

Information leakage in YAQL

Moderate severity GitHub Reviewed Published Mar 18, 2024 to the GitHub Advisory Database • Updated Mar 28, 2024

Package

pip yaql (pip)

Affected versions

< 3.0.0

Patched versions

3.0.0

Description

YAQL before 3.0.0 is used in Murano, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

References

Published by the National Vulnerability Database Mar 18, 2024
Published to the GitHub Advisory Database Mar 18, 2024
Reviewed Mar 18, 2024
Last updated Mar 28, 2024

Severity

Moderate

EPSS score

0.045%
(17th percentile)

Weaknesses

CVE ID

CVE-2024-29156

GHSA ID

GHSA-mvf6-hwxh-7v76

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.