[Openstack-security] [Bug 1586078] Fix included in openstack/python-muranoclient 0.7.3

Doug Hellmann doug at doughellmann.com
Mon Jun 27 12:26:17 UTC 2016


This issue was fixed in the openstack/python-muranoclient 0.7.3 release.

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1586078

Title:
  YaqlYamlLoader inherits from YamlLoader

Status in python-muranoclient:
  Fix Released
Status in python-muranoclient kilo series:
  Won't Fix
Status in python-muranoclient liberty series:
  Fix Committed
Status in python-muranoclient mitaka series:
  Fix Committed
Status in python-muranoclient newton series:
  Fix Released

Bug description:
  YaqlYamlLoader inherits from YamlLoader, meaning that it is possible
  to use extended unsafe tags in yaml files
  http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes

To manage notifications about this bug go to:
https://bugs.launchpad.net/python-muranoclient/+bug/1586078/+subscriptions




More information about the Openstack-security mailing list