VDB

PYSEC-2020-176

PYSEC-2020-176 PUBLISHED

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

Affected Products

VendorProductVersions
PyPIpyyaml5.1, 5.1, 5.1.1

Timeline

  • Feb 19, 2020 CVE Published
  • Nov 8, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›