QID 983497
QID 983497: Python (pip) Security Update for django-piston (GHSA-pvhp-v9qp-xf5r)
emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.
Django Tastypie has a very similar vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pvhp-v9qp-xf5r for updates pertaining to this vulnerability.
Vendor References
- GHSA-pvhp-v9qp-xf5r -
github.com/advisories/GHSA-pvhp-v9qp-xf5r
CVEs related to QID 983497
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pvhp-v9qp-xf5r | django-piston |
|
|
| GHSA-pvhp-v9qp-xf5r | django-tastypie |
|