A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python38-scipyUpgrade python38-markupsafeUpgrade python38-mod_wsgiUpgrade python38-psycopg2Upgrade python38-pysocksUpgrade python38-chardetUpgrade python38-cryptographyUpgrade python38-pycparserUpgrade python38-pytzUpgrade python38-asn1cryptoUpgrade python38-CythonUpgrade python38-requestsUpgrade python38-psycopg2-testsUpgrade python38-cffiUpgrade python38-psycopg2-docUpgrade python38-idna | May 4, 2022 | Mar 24, 2020 |
| Alpine Linux | — | Upgrade py3-yaml | Aug 22, 2024 | Mar 24, 2020 |
| Centos_linux | — | Upgrade python38-asn1cryptoUpgrade python38-psycopg2Upgrade python38-tkinterUpgrade python-psycopg2-debugsourceUpgrade python38-lxmlUpgrade python38-wheelUpgrade python38-pytzUpgrade python38-pyyamlUpgrade python38-psutil-debuginfoUpgrade python38-Cython-debuginfoUpgrade python38-cffi-debuginfoUpgrade python38-cryptography-debuginfoUpgrade python38-requestsUpgrade python38-debuginfoUpgrade numpy-debugsourceUpgrade python38-debugUpgrade python-markupsafe-debugsourceUpgrade python38-numpy-f2pyUpgrade python38-rpm-macrosUpgrade python38-jinja2Upgrade python38-markupsafe-debuginfoUpgrade python38-setuptoolsUpgrade python38-psycopg2-docUpgrade Cython-debugsourceUpgrade python38-develUpgrade python38-wheel-wheelUpgrade python-cryptography-debugsourceUpgrade python-lxml-debugsourceUpgrade python38-chardetUpgrade python38-scipyUpgrade python38-psycopg2-debuginfoUpgrade python38-plyUpgrade python38-mod_wsgiUpgrade python38-numpy-docUpgrade python38-setuptools-wheelUpgrade python38-psycopg2-testsUpgrade python38-cffiUpgrade python38-numpyUpgrade python38-cryptographyUpgrade python38-pip-wheelUpgrade python38Upgrade python38-pipUpgrade scipy-debugsourceUpgrade python38-urllib3Upgrade python38-sixUpgrade python38-idnaUpgrade python38-CythonUpgrade python-cffi-debugsourceUpgrade python38-debugsourceUpgrade python38-pysocksUpgrade python38-babelUpgrade python38-PyMySQLUpgrade python38-scipy-debuginfoUpgrade PyYAML-debugsourceUpgrade python38-markupsafeUpgrade python38-libsUpgrade python38-numpy-debuginfoUpgrade python38-psutilUpgrade python38-pyyaml-debuginfoUpgrade python38-lxml-debuginfoUpgrade python38-testUpgrade python38-idleUpgrade python-psutil-debugsourceUpgrade python38-pycparser | Nov 5, 2020 | Mar 24, 2020 |
| Debian | — | Upgrade pyyaml | Jul 30, 2024 | Mar 24, 2020 |
| Freebsd | — | Upgrade py38-yamlUpgrade py36-yamlUpgrade py27-yamlUpgrade py35-yamlUpgrade py37-yaml | Apr 28, 2020 | Apr 27, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Jul 20, 2021 | Mar 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python2-pyyamlUpgrade python3-pyyaml | Jul 31, 2020 | Mar 24, 2020 |
| Oracle Solaris | — | Upgrade library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-37 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-39 to version 5.4.1-11.4.33.0.1.94.0 on Solaris 11.4Upgrade library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-27 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4 | Jan 19, 2021 | Mar 24, 2020 |
| Oracle_linux | — | Upgrade python38-idleUpgrade python38-cryptographyUpgrade python38-chardetUpgrade python38-jinja2Upgrade python38Upgrade python38-scipyUpgrade python38-pip-wheelUpgrade python38-tkinterUpgrade python38-lxmlUpgrade python38-setuptoolsUpgrade python38-babelUpgrade python38-mod_wsgiUpgrade python38-develUpgrade python38-plyUpgrade python38-pysocksUpgrade python38-urllib3Upgrade python38-pyyamlUpgrade python38-markupsafeUpgrade python38-requestsUpgrade python38-wheel-wheelUpgrade python38-CythonUpgrade python38-cffiUpgrade python38-psycopg2-testsUpgrade python38-numpyUpgrade python38-libsUpgrade python38-psycopg2-docUpgrade python38-debugUpgrade python38-asn1cryptoUpgrade python38-psycopg2Upgrade python38-numpy-docUpgrade python38-pytzUpgrade python38-idnaUpgrade python38-PyMySQLUpgrade python38-psutilUpgrade python38-setuptools-wheelUpgrade python38-pycparserUpgrade python38-wheelUpgrade python38-pipUpgrade python38-numpy-f2pyUpgrade python38-rpm-macrosUpgrade python38-testUpgrade python38-six | Jul 22, 2024 | Mar 2, 2020 |
| Redhat_linux | — | Upgrade python38-cffiUpgrade python-lxml-debugsourceUpgrade python38-scipyUpgrade python-psycopg2-debugsourceUpgrade python38-Cython-debuginfoUpgrade python38-scipy-debuginfoUpgrade python38-debugsourceUpgrade python38-babelUpgrade python38-numpy-docUpgrade python38-psutilUpgrade python38-pycparserUpgrade python38-setuptools-wheelUpgrade python38-jinja2Upgrade python38-libsUpgrade python38-psycopg2-docUpgrade python38-urllib3Upgrade python38-cryptographyUpgrade python38-numpyUpgrade python38-psycopg2-testsUpgrade scipy-debugsourceUpgrade python38-pip-wheelUpgrade python38-pyyaml-debuginfoUpgrade python38-plyUpgrade python38-psycopg2-debuginfoUpgrade python38-idnaUpgrade numpy-debugsourceUpgrade python-psutil-debugsourceUpgrade python-cffi-debugsourceUpgrade python38-chardetUpgrade python38-sixUpgrade python38Upgrade python38-lxml-debuginfoUpgrade python38-cryptography-debuginfoUpgrade python38-testUpgrade python38-markupsafe-debuginfoUpgrade python38-lxmlUpgrade python38-idleUpgrade python38-debugUpgrade python38-debuginfoUpgrade python38-tkinterUpgrade python38-rpm-macrosUpgrade python-cryptography-debugsourceUpgrade python38-pysocksUpgrade python38-wheel-wheelUpgrade python38-requestsUpgrade python38-pipUpgrade Cython-debugsourceUpgrade python38-mod_wsgiUpgrade python38-psycopg2Upgrade python38-markupsafeUpgrade python38-numpy-f2pyUpgrade python38-pytzUpgrade python38-develUpgrade python38-setuptoolsUpgrade python38-wheelUpgrade python38-pyyamlUpgrade python38-cffi-debuginfoUpgrade python-markupsafe-debugsourceUpgrade python38-PyMySQLUpgrade python38-asn1cryptoUpgrade PyYAML-debugsourceUpgrade python38-CythonUpgrade python38-psutil-debuginfoUpgrade python38-numpy-debuginfo | Nov 5, 2020 | Mar 24, 2020 |
| Rocky_linux | — | Upgrade scipy-debugsourceUpgrade python38-psycopg2-docUpgrade python-cffi-debugsourceUpgrade python38-psycopg2-debuginfoUpgrade python38-cffiUpgrade python38-psycopg2-testsUpgrade python-psycopg2-debugsourceUpgrade python38-scipy-debuginfoUpgrade python38-cryptography-debuginfoUpgrade python38-cryptographyUpgrade python38-psutilUpgrade python38-Cython-debuginfoUpgrade python38-numpyUpgrade python-psutil-debugsourceUpgrade python38-markupsafe-debuginfoUpgrade python38-numpy-f2pyUpgrade numpy-debugsourceUpgrade python38-pyyaml-debuginfoUpgrade Cython-debugsourceUpgrade PyYAML-debugsourceUpgrade python38-pyyamlUpgrade python38-markupsafeUpgrade python38-CythonUpgrade python38-numpy-debuginfoUpgrade python38-scipyUpgrade python38-psutil-debuginfoUpgrade python38-mod_wsgiUpgrade python-cryptography-debugsourceUpgrade python38-cffi-debuginfoUpgrade python38-psycopg2Upgrade python-markupsafe-debugsource | Mar 12, 2024 | Mar 24, 2020 |
| Suse | — | Upgrade python3-pyyamlUpgrade python-pyyamlUpgrade python2-pyyaml | Apr 12, 2020 | Mar 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub