Логотип exploitDog
bind:CVE-2022-31605
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31605

Количество 2

Количество 2

nvd логотип

CVE-2022-31605

больше 3 лет назад

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hrf3-622q-8366

больше 3 лет назад

Unsafe yaml deserialization in NVFlare

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31605

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-hrf3-622q-8366

Unsafe yaml deserialization in NVFlare

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу