CVE-2016-4972: Input Validation
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows remote attackers to create arbitrary Python objects and execute arbitrary code via crafted extended YAML tags in UI definitions in packages.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4972?
CVE-2016-4972 has been classified as a moderate severity vulnerability due to potential unauthorized code execution risks.
How do I fix CVE-2016-4972?
To fix CVE-2016-4972, upgrade Murano to version 1.0.3, Murano-dashboard to version 1.0.3, and python-muranoclient to version 0.8.5 or later.
Which versions are affected by CVE-2016-4972?
CVE-2016-4972 affects OpenStack Murano versions prior to 1.0.3, Murano-dashboard versions prior to 1.0.3, and python-muranoclient versions prior to 0.7.3.
What are the consequences of CVE-2016-4972?
The consequences of CVE-2016-4972 include the risk of attackers executing arbitrary code within the OpenStack environment.
Is there a workaround for CVE-2016-4972?
There is no official workaround for CVE-2016-4972; the only solution is to upgrade to the patched versions.