A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python38-cryptographyUpgrade python38-markupsafeUpgrade python38-pysocksUpgrade python38-psycopg2Upgrade python38-mod_wsgiUpgrade python38-chardetUpgrade python38-scipyUpgrade python38-pytzUpgrade python38-psycopg2-docUpgrade python38-cffiUpgrade python38-requestsUpgrade python38-psycopg2-testsUpgrade python38-CythonUpgrade python38-pycparserUpgrade python38-idnaUpgrade python38-asn1crypto | May 4, 2022 | Mar 24, 2020 |
| Alpine Linux | — | Upgrade py3-yaml | Aug 22, 2024 | Mar 24, 2020 |
| Centos_linux | — | Upgrade python38-idnaUpgrade python38-setuptools-wheelUpgrade python38-numpy-debuginfoUpgrade python38-plyUpgrade python38-numpyUpgrade python38-cffiUpgrade python38-scipy-debuginfoUpgrade python-cffi-debugsourceUpgrade python38-PyMySQLUpgrade python38-cryptographyUpgrade python38-psutilUpgrade python38-psycopg2-debuginfoUpgrade python38-scipyUpgrade python38-debugsourceUpgrade scipy-debugsourceUpgrade python38-numpy-docUpgrade python38-pysocksUpgrade python38-mod_wsgiUpgrade python38-pyyaml-debuginfoUpgrade python38-psycopg2-testsUpgrade python38Upgrade python38-chardetUpgrade python38-libsUpgrade python-lxml-debugsourceUpgrade python38-pip-wheelUpgrade python38-urllib3Upgrade python38-babelUpgrade python38-markupsafeUpgrade python38-pipUpgrade python38-CythonUpgrade python38-sixUpgrade PyYAML-debugsourceUpgrade python38-testUpgrade python38-lxml-debuginfoUpgrade python-psutil-debugsourceUpgrade python38-idleUpgrade python38-pycparserUpgrade python38-Cython-debuginfoUpgrade python38-cffi-debuginfoUpgrade python38-psycopg2Upgrade python38-pyyamlUpgrade python38-setuptoolsUpgrade python38-requestsUpgrade python-cryptography-debugsourceUpgrade python38-wheel-wheelUpgrade python38-lxmlUpgrade python38-wheelUpgrade python-psycopg2-debugsourceUpgrade python38-jinja2Upgrade python38-asn1cryptoUpgrade python38-debuginfoUpgrade python38-psutil-debuginfoUpgrade numpy-debugsourceUpgrade python38-numpy-f2pyUpgrade python38-develUpgrade python38-rpm-macrosUpgrade python-markupsafe-debugsourceUpgrade Cython-debugsourceUpgrade python38-markupsafe-debuginfoUpgrade python38-debugUpgrade python38-pytzUpgrade python38-tkinterUpgrade python38-psycopg2-docUpgrade python38-cryptography-debuginfo | Nov 5, 2020 | Mar 24, 2020 |
| Debian | — | Upgrade pyyaml | Jul 30, 2024 | Mar 24, 2020 |
| Freebsd | — | Upgrade py36-yamlUpgrade py38-yamlUpgrade py37-yamlUpgrade py27-yamlUpgrade py35-yaml | Apr 28, 2020 | Apr 27, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Jul 20, 2021 | Mar 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python2-pyyamlUpgrade python3-pyyaml | Jul 31, 2020 | Mar 24, 2020 |
| Oracle Solaris | — | Upgrade library/python/pyyaml to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-27 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-37 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-39 to version 5.4.1-11.4.33.0.1.94.0 on Solaris 11.4Upgrade library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4 | Jan 19, 2021 | Mar 24, 2020 |
| Oracle_linux | — | Upgrade python38-tkinterUpgrade python38-jinja2Upgrade python38-lxmlUpgrade python38-cryptographyUpgrade python38-chardetUpgrade python38-idleUpgrade python38-wheel-wheelUpgrade python38-pysocksUpgrade python38-pyyamlUpgrade python38-develUpgrade python38-urllib3Upgrade python38-requestsUpgrade python38-markupsafeUpgrade python38-plyUpgrade python38-setuptoolsUpgrade python38-mod_wsgiUpgrade python38-babelUpgrade python38-pip-wheelUpgrade python38-scipyUpgrade python38Upgrade python38-numpyUpgrade python38-libsUpgrade python38-numpy-docUpgrade python38-psutilUpgrade python38-rpm-macrosUpgrade python38-psycopg2-testsUpgrade python38-sixUpgrade python38-psycopg2-docUpgrade python38-pycparserUpgrade python38-wheelUpgrade python38-pipUpgrade python38-asn1cryptoUpgrade python38-debugUpgrade python38-psycopg2Upgrade python38-numpy-f2pyUpgrade python38-pytzUpgrade python38-CythonUpgrade python38-cffiUpgrade python38-setuptools-wheelUpgrade python38-idnaUpgrade python38-PyMySQLUpgrade python38-test | Jul 22, 2024 | Mar 2, 2020 |
| Redhat_linux | — | Upgrade python38-pyyamlUpgrade python38-pipUpgrade python38-idleUpgrade python38-mod_wsgiUpgrade python38-markupsafeUpgrade python38-asn1cryptoUpgrade python38-setuptoolsUpgrade python38-requestsUpgrade python38-psycopg2Upgrade python-cryptography-debugsourceUpgrade python38-debuginfoUpgrade python38-tkinterUpgrade python38-rpm-macrosUpgrade python38-pytzUpgrade python-markupsafe-debugsourceUpgrade python38-PyMySQLUpgrade python38-numpy-debuginfoUpgrade python38-CythonUpgrade python38-pysocksUpgrade python38-wheel-wheelUpgrade PyYAML-debugsourceUpgrade python38-numpy-f2pyUpgrade Cython-debugsourceUpgrade python38-lxmlUpgrade python38-debugUpgrade python38-psutil-debuginfoUpgrade python38-wheelUpgrade python38-markupsafe-debuginfoUpgrade python38-develUpgrade python38-cffi-debuginfoUpgrade python-lxml-debugsourceUpgrade python38-cryptographyUpgrade python-psutil-debugsourceUpgrade numpy-debugsourceUpgrade python38-plyUpgrade python-cffi-debugsourceUpgrade python38-scipyUpgrade python38-scipy-debuginfoUpgrade python38-cryptography-debuginfoUpgrade python38Upgrade python38-lxml-debuginfoUpgrade python38-idnaUpgrade python38-pyyaml-debuginfoUpgrade python38-babelUpgrade python38-psycopg2-debuginfoUpgrade python38-sixUpgrade python38-Cython-debuginfoUpgrade python38-debugsourceUpgrade python38-pip-wheelUpgrade python38-numpy-docUpgrade python38-pycparserUpgrade python38-numpyUpgrade python-psycopg2-debugsourceUpgrade python38-jinja2Upgrade python38-urllib3Upgrade scipy-debugsourceUpgrade python38-cffiUpgrade python38-libsUpgrade python38-chardetUpgrade python38-testUpgrade python38-psycopg2-testsUpgrade python38-psutilUpgrade python38-psycopg2-docUpgrade python38-setuptools-wheel | Nov 5, 2020 | Mar 24, 2020 |
| Rocky_linux | — | Upgrade python-markupsafe-debugsourceUpgrade python38-cffi-debuginfoUpgrade python38-pyyamlUpgrade python38-psycopg2Upgrade python38-scipyUpgrade python38-psutil-debuginfoUpgrade PyYAML-debugsourceUpgrade python38-markupsafeUpgrade python38-mod_wsgiUpgrade python38-CythonUpgrade python38-numpy-debuginfoUpgrade Cython-debugsourceUpgrade python-cryptography-debugsourceUpgrade python-psycopg2-debugsourceUpgrade scipy-debugsourceUpgrade python-cffi-debugsourceUpgrade python38-psycopg2-debuginfoUpgrade python38-numpy-f2pyUpgrade numpy-debugsourceUpgrade python38-pyyaml-debuginfoUpgrade python38-markupsafe-debuginfoUpgrade python38-numpyUpgrade python38-cffiUpgrade python38-cryptography-debuginfoUpgrade python38-cryptographyUpgrade python38-psutilUpgrade python-psutil-debugsourceUpgrade python38-Cython-debuginfoUpgrade python38-psycopg2-docUpgrade python38-scipy-debuginfoUpgrade python38-psycopg2-tests | Mar 12, 2024 | Mar 24, 2020 |
| Suse | — | Upgrade python2-pyyamlUpgrade python-pyyamlUpgrade python3-pyyaml | Apr 12, 2020 | Mar 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub