CVE-2017-18342
Summary
| CVE | CVE-2017-18342 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-27 12:29:00 UTC |
| Updated | 2023-11-07 02:41:00 UTC |
| Description | In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PyYAML yaml.load(input) Deprecation · yaml/pyyaml Wiki · GitHub |
|
github.com |
|
| [SECURITY] Fedora 30 Update: PyYAML-5.1-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| PyYAML: Arbitrary code execution (GLSA 202003-45) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| pyyaml/CHANGES at master · yaml/pyyaml · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| [SECURITY] Fedora 29 Update: PyYAML-5.1-1.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: PyYAML-5.1-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 29 Update: PyYAML-5.1-1.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Use 'yaml.safe_load' in 'load_yaml_from_docstring' · Issue #278 · marshmallow-code/apispec · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: PyYAML-5.1-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| PyYAML 4.2 Release Plan · Issue #193 · yaml/pyyaml · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: PyYAML-5.1-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| PyYAML yaml.load(input) Deprecation · yaml/pyyaml Wiki · GitHub |
MISC |
github.com |
Third Party Advisory |
| Make pyyaml safe by default. by alex · Pull Request #74 · yaml/pyyaml · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159768 Oracle Enterprise Linux Security Update for ol-automation-manager (ELSA-2022-9341)
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 904846 Common Base Linux Mariner (CBL-Mariner) Security Update for mozjs60 (12374)
- 904919 Common Base Linux Mariner (CBL-Mariner) Security Update for PyYAML (12295)
- 904980 Common Base Linux Mariner (CBL-Mariner) Security Update for PyYAML (12458)
- 980984 Python (pip) Security Update for pyyaml (GHSA-rprw-h62v-c2w7)