QID 982731

QID 982731: Python (pip) Security Update for pyyaml (GHSA-3pqx-4fqf-j49f)

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-3pqx-4fqf-j49f for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982731

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3pqx-4fqf-j49f pyyaml URL Logo github.com/advisories/GHSA-3pqx-4fqf-j49f