QID 982731
QID 982731: Python (pip) Security Update for pyyaml (GHSA-3pqx-4fqf-j49f)
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3pqx-4fqf-j49f for updates pertaining to this vulnerability.
Vendor References
- GHSA-3pqx-4fqf-j49f -
github.com/advisories/GHSA-3pqx-4fqf-j49f
CVEs related to QID 982731
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3pqx-4fqf-j49f | pyyaml |
|