All vulnerabilities

CVE-2019-20477

Deserialization of Untrusted Data in PyYAML

Description

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
RPM
Publish Date
February 18, 2020
Modified Date
November 7, 2023
Score Vector
Affected Versions