Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-9341

Опубликовано: 27 апр. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-9341: ol-automation-manager security update (IMPORTANT)

[1.0.2-1.el8]

  • Fix multiple CVEs : CVE-2017-18342, CVE-2020-10109, CVE-2020-10108, CVE-2021-33203, CVE-2021-33571, CVE-2021-44420, CVE-2021-31542, CVE-2021-28658, CVE-2021-28957, CVE-2021-43818, CVE-2020-27783 [Orabug: 34109801]

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.

CVSS3: 8.1
redhat
почти 7 лет назад

In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.

CVSS3: 9.8
nvd
почти 7 лет назад

In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.

CVSS3: 9.8
debian
почти 7 лет назад

In PyYAML before 5.1, the yaml.load() API could execute arbitrary code ...

CVSS3: 9.8
github
больше 6 лет назад

PyYAML insecurely deserializes YAML strings leading to arbitrary code execution