QID 981403
QID 981403: Python (pip) Security Update for sqla-yaml-fixtures (GHSA-2x54-j4m3-r6wx)
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2x54-j4m3-r6wx for updates pertaining to this vulnerability.
Vendor References
- GHSA-2x54-j4m3-r6wx -
github.com/advisories/GHSA-2x54-j4m3-r6wx
CVEs related to QID 981403
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2x54-j4m3-r6wx | sqla-yaml-fixtures |
|