First published: Mon Apr 22 2024(Updated: )
Heat templates for TripleO<br>YAQL library has a out of the box large set of commonly used functions.<br>Security Fix(es):<br><li> OpenStack Murano Component Information Leakage (CVE-2024-29156)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openstack-tripleo-heat-templates | <14.3.1-17.1.20231103010826.2.el9 | 14.3.1-17.1.20231103010826.2.el9 |
redhat/python-yaql | <1.1.3-11.el9 | 1.1.3-11.el9 |
redhat/python3-yaql | <1.1.3-11.el9 | 1.1.3-11.el9 |
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:1931 is classified as important.
RHSA-2024:1931 addresses information leakage in the OpenStack Murano component, identified as CVE-2024-29156.
To fix RHSA-2024:1931, update to the remedied versions of the affected packages including openstack-tripleo-heat-templates, python-yaql, and python3-yaql.
RHSA-2024:1931 affects the openstack-tripleo-heat-templates, python-yaql, and python3-yaql packages.
Yes, RHSA-2024:1931 includes a CVSS score indicating the impact of the vulnerability, but specific details are not provided.