Описание
An exploitable vulnerability exists in the YAML parsing functionality in the YAMLParser method in Interfaces.py in PyAnyAPI before 0.6.1. A YAML parser can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability.
Ссылки
- Issue Tracking
- Release Notes
- Third Party Advisory
- Product
- Issue Tracking
- Release Notes
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 0.6.1 (исключая)
cpe:2.3:a:pyanyapi_project:pyanyapi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.0119
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
EPSS
Процентиль: 78%
0.0119
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
NVD-CWE-noinfo