CVE-2016-4972

Description

OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows remote attackers to create arbitrary Python objects and execute arbitrary code via crafted extended YAML tags in UI definitions in packages.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.928

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-4972 are fixed in Python-murano 1.0.3Windows
Vulnerabilities CVE-2016-4972 are fixed in Python-murano-dashboard 1.0.3Windows
Vulnerabilities CVE-2016-4972 are fixed in Python-murano-dashboard 2.0.1Windows
Vulnerabilities CVE-2016-4972 are fixed in Python-python-muranoclient 0.7.3Windows
Vulnerabilities CVE-2016-4972 are fixed in Python-python-muranoclient 0.8.5Windows
Vulnerabilities CVE-2016-4972 are fixed in Python-murano for linux 1.0.3Linux
Vulnerabilities CVE-2016-4972 are fixed in Python-murano-dashboard for linux 1.0.3Linux
Vulnerabilities CVE-2016-4972 are fixed in Python-murano-dashboard for linux 2.0.1Linux
Vulnerabilities CVE-2016-4972 are fixed in Python-python-muranoclient for linux 0.7.3Linux
Vulnerabilities CVE-2016-4972 are fixed in Python-python-muranoclient for linux 0.8.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234