QID 996737

Date Published: 2024-01-17

QID 996737: Python (Pip) Security Update for django-tastypie (GHSA-qgvw-qc2q-gv5q)

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-qgvw-qc2q-gv5q for updates and patch information.
    Vendor References

    CVEs related to QID 996737

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qgvw-qc2q-gv5q django-tastypie URL Logo github.com/advisories/GHSA-qgvw-qc2q-gv5q