YaqlYamlLoader inherits from YamlLoader
Bug #1586079 reported by
Kirill Zaitsev
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Murano |
Fix Released
|
Critical
|
Kirill Zaitsev | ||
Kilo |
Won't Fix
|
Critical
|
Unassigned | ||
Liberty |
Fix Released
|
Critical
|
Kirill Zaitsev | ||
Mitaka |
Fix Released
|
Critical
|
Kirill Zaitsev | ||
Newton |
Fix Released
|
Critical
|
Kirill Zaitsev |
Bug Description
YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://
Both dashboard, engine/api seem to be vulnerable.
CVE References
description: | updated |
Changed in murano: | |
milestone: | newton-1 → newton-2 |
information type: | Private Security → Public Security |
description: | updated |
To post a comment you must log in.
Patch for the murano-dashboard