CVE-2024-29156: Information leakage in YAQL
YAQL before 3.0.0 is used in Murano, the Murano service’s MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.
References
Detect and mitigate CVE-2024-29156 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →