QID 996737
Date Published: 2024-01-17
QID 996737: Python (Pip) Security Update for django-tastypie (GHSA-qgvw-qc2q-gv5q)
The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qgvw-qc2q-gv5q for updates and patch information.
Vendor References
- GHSA-qgvw-qc2q-gv5q -
github.com/advisories/GHSA-qgvw-qc2q-gv5q
CVEs related to QID 996737
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qgvw-qc2q-gv5q | django-tastypie |
|