RHSA-2024:1930: Important: Red Hat OpenStack Platform 17.1 (openstack-tripleo-heat-templates and python-yaql) security update
Heat templates for TripleOYAQL library has a out of the box large set of commonly used functions.Security Fix(es): OpenStack Murano Component Information Leakage (CVE-2024-29156) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Other sources
Important: Red Hat OpenStack Platform 17.1 (openstack-tripleo-heat-templates and python-yaql) security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1930?
The severity of RHSA-2024:1930 is classified as important.
What vulnerabilities are addressed in RHSA-2024:1930?
RHSA-2024:1930 addresses the OpenStack Murano Component Information Leakage vulnerability identified by CVE-2024-29156.
How do I fix RHSA-2024:1930?
To fix RHSA-2024:1930, update the affected packages to the specified remedied versions provided in the advisory.
Which packages are affected by RHSA-2024:1930?
The affected packages in RHSA-2024:1930 include openstack-tripleo-heat-templates, python-yaql, and python3-yaql.
What versions of the packages need to be updated for RHSA-2024:1930?
The packages need to be updated to openstack-tripleo-heat-templates version 14.3.1-17.1.20231103003748.2.el8 and python-yaql/python3-yaql version 1.1.3-11.el8.