All vulnerabilities
CVE-2019-20477
Deserialization of Untrusted Data in PyYAML
Description
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
RPM
Publish Date
February 18, 2020
Modified Date
November 7, 2023
Score Vector
Affected Versions

