[murano] YaqlYamlLoader inherits from YamlLoader
Bug #1593002 reported by
Kirill Zaitsev
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mirantis OpenStack |
Fix Released
|
Critical
|
Kirill Zaitsev | ||
5.1.x |
In Progress
|
Critical
|
MOS Maintenance | ||
6.0.x |
In Progress
|
Critical
|
MOS Maintenance | ||
6.1.x |
Fix Released
|
Critical
|
MOS Maintenance | ||
7.0.x |
Fix Released
|
Critical
|
MOS Maintenance | ||
8.0.x |
Fix Released
|
Critical
|
MOS Maintenance | ||
9.x |
Fix Released
|
Critical
|
Kirill Zaitsev |
Bug Description
YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://
dashboard, engine/api, and client are vulnerable.
CVE Description:
Kirill Zaitsev from Mirantis reported a vulnerability in OpenStack Murano applications processing. Using extended YAML tags in Murano application YAML files, an attacker can perform a Remote Code Execution attack.
CVE References
tags: | added: feature-security |
information type: | Private Security → Public Security |
information type: | Public Security → Private Security |
information type: | Private Security → Public Security |
description: | updated |
To post a comment you must log in.
Setting to In Progress for 6.1-updates, 7.0-updates, 8.0-updates, the link to reviews is https:/ /review. fuel-infra. org/#/q/ topic:bug/ 1593002