QID 995943
Date Published: 2023-11-16
QID 995943: Python (Pip) Security Update for remarshal (GHSA-gw7g-qr8w-3448)
Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack. Processing untrusted YAML files may cause a denial-of-service (DoS) condition.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gw7g-qr8w-3448 for updates and patch information.
Vendor References
- GHSA-gw7g-qr8w-3448 -
github.com/advisories/GHSA-gw7g-qr8w-3448
CVEs related to QID 995943
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gw7g-qr8w-3448 | remarshal |
|