UNKNOWN OpenStack
CVE-2024-29156
OSSN-0093: = Unsafe Environment Handling in MuranoPL =
The Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information. Murano is an inactive project, so no fix is currently under development for this vulnerability. It is strongly recommended that any OpenStack deployments disable or fully remove Murano, if installed, at the earliest opportunity.
Affected Products
- CVE-2024-29156
References
This unknown severity vulnerability was published on 2026-08-27 via OpenStack. Affected: CVE-2024-29156.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.