QID 981149
QID 981149: Python (pip) Security Update for django_make_app (GHSA-9pv8-q5rx-c8gq)
An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9pv8-q5rx-c8gq for updates pertaining to this vulnerability.
Vendor References
- GHSA-9pv8-q5rx-c8gq -
github.com/advisories/GHSA-9pv8-q5rx-c8gq
CVEs related to QID 981149
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9pv8-q5rx-c8gq | django_make_app |
|