CVE-2016-4972

Description

A flaw was discovered in openstack-murano processing. Using extended YAML tags in Murano-application YAML files, an attacker could perform remote code execution.

Statement

Red Hat OpenStack Platform and Red Hat Enterprise Linux OpenStack Platform do not include or support openstack-murano, and are therefore not affected by this flaw in any supported configuration.

Acknowledgements

Red Hat would like to thank Kirill Zaitsev (Mirantis) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.