A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python38-cffiUpgrade python38-pycparserUpgrade python38-pytzUpgrade python38-asn1cryptoUpgrade python38-psycopg2-testsUpgrade python38-idnaUpgrade python38-requestsUpgrade python38-psycopg2-docUpgrade python38-CythonUpgrade python38-chardetUpgrade python38-markupsafeUpgrade python38-cryptographyUpgrade python38-mod_wsgiUpgrade python38-pysocksUpgrade python38-scipyUpgrade python38-psycopg2 | May 4, 2022 | Mar 24, 2020 |
| Alpine Linux | — | Upgrade py3-yaml | Aug 22, 2024 | Mar 24, 2020 |
| Centos_linux | — | Upgrade python38-pip-wheelUpgrade python38-pyyaml-debuginfoUpgrade python38-scipy-debuginfoUpgrade python-cffi-debugsourceUpgrade python38-numpy-debuginfoUpgrade python38-cffiUpgrade python38-PyMySQLUpgrade python38-idleUpgrade python38-numpyUpgrade python38-testUpgrade python38-cryptographyUpgrade python38-debugsourceUpgrade python38-libsUpgrade python38-lxml-debuginfoUpgrade python38-setuptools-wheelUpgrade python38-markupsafeUpgrade python38-mod_wsgiUpgrade python38-pysocksUpgrade python-psutil-debugsourceUpgrade python38-numpy-docUpgrade PyYAML-debugsourceUpgrade python-lxml-debugsourceUpgrade python38-babelUpgrade python38-psycopg2-testsUpgrade python38-pycparserUpgrade python38-plyUpgrade python38-psutilUpgrade python38-scipyUpgrade python38-CythonUpgrade python38-chardetUpgrade python38-idnaUpgrade python38-sixUpgrade python38Upgrade python38-psycopg2-debuginfoUpgrade python38-urllib3Upgrade scipy-debugsourceUpgrade python38-pipUpgrade python38-wheelUpgrade python38-debugUpgrade python38-requestsUpgrade python38-develUpgrade python38-asn1cryptoUpgrade python38-numpy-f2pyUpgrade numpy-debugsourceUpgrade python-markupsafe-debugsourceUpgrade python38-cryptography-debuginfoUpgrade python38-cffi-debuginfoUpgrade python38-setuptoolsUpgrade python38-pyyamlUpgrade python38-markupsafe-debuginfoUpgrade python38-Cython-debuginfoUpgrade python-cryptography-debugsourceUpgrade python38-wheel-wheelUpgrade python38-lxmlUpgrade python-psycopg2-debugsourceUpgrade python38-rpm-macrosUpgrade Cython-debugsourceUpgrade python38-pytzUpgrade python38-psycopg2Upgrade python38-psutil-debuginfoUpgrade python38-debuginfoUpgrade python38-psycopg2-docUpgrade python38-tkinterUpgrade python38-jinja2 | Nov 5, 2020 | Mar 24, 2020 |
| Debian | — | Upgrade pyyaml | Jul 30, 2024 | Mar 24, 2020 |
| Freebsd | — | Upgrade py36-yamlUpgrade py38-yamlUpgrade py37-yamlUpgrade py35-yamlUpgrade py27-yaml | Apr 28, 2020 | Apr 27, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Jul 20, 2021 | Mar 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-pyyamlUpgrade python2-pyyaml | Jul 31, 2020 | Mar 24, 2020 |
| Oracle Solaris | — | Upgrade library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-27 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-37 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-39 to version 5.4.1-11.4.33.0.1.94.0 on Solaris 11.4 | Jan 19, 2021 | Mar 24, 2020 |
| Oracle_linux | — | Upgrade python38-wheelUpgrade python38-rpm-macrosUpgrade python38-pipUpgrade python38-testUpgrade python38-pycparserUpgrade python38-psutilUpgrade python38-psycopg2Upgrade python38-numpy-f2pyUpgrade python38-pytzUpgrade python38-idnaUpgrade python38-PyMySQLUpgrade python38-cffiUpgrade python38-CythonUpgrade python38-debugUpgrade python38-numpy-docUpgrade python38-psycopg2-docUpgrade python38-numpyUpgrade python38-asn1cryptoUpgrade python38-sixUpgrade python38-setuptools-wheelUpgrade python38-libsUpgrade python38-psycopg2-testsUpgrade python38-develUpgrade python38-markupsafeUpgrade python38-setuptoolsUpgrade python38-pysocksUpgrade python38-babelUpgrade python38-tkinterUpgrade python38-lxmlUpgrade python38-pyyamlUpgrade python38-requestsUpgrade python38-urllib3Upgrade python38-jinja2Upgrade python38-wheel-wheelUpgrade python38-scipyUpgrade python38-cryptographyUpgrade python38-chardetUpgrade python38-idleUpgrade python38Upgrade python38-pip-wheelUpgrade python38-plyUpgrade python38-mod_wsgi | Jul 22, 2024 | Mar 2, 2020 |
| Redhat_linux | — | Upgrade python38-PyMySQLUpgrade python38-pyyamlUpgrade PyYAML-debugsourceUpgrade python38-cffi-debuginfoUpgrade python38-wheel-wheelUpgrade python38-setuptoolsUpgrade python38-debugUpgrade python38-numpy-debuginfoUpgrade python-markupsafe-debugsourceUpgrade python38-requestsUpgrade python38-pytzUpgrade python-cryptography-debugsourceUpgrade python38-debuginfoUpgrade Cython-debugsourceUpgrade python38-pysocksUpgrade python38-numpy-f2pyUpgrade python38-CythonUpgrade python38-asn1cryptoUpgrade python38-develUpgrade python38-mod_wsgiUpgrade python38-markupsafeUpgrade python38-rpm-macrosUpgrade python38-markupsafe-debuginfoUpgrade python38-tkinterUpgrade python38-idleUpgrade python38-psutil-debuginfoUpgrade python38-wheelUpgrade python38-pipUpgrade python38-psycopg2Upgrade python38-lxmlUpgrade python38-psycopg2-testsUpgrade python-cffi-debugsourceUpgrade python38-plyUpgrade numpy-debugsourceUpgrade python38-numpyUpgrade python38-jinja2Upgrade python-lxml-debugsourceUpgrade scipy-debugsourceUpgrade python38-chardetUpgrade python38-Cython-debuginfoUpgrade python38-testUpgrade python38-sixUpgrade python38-libsUpgrade python38-debugsourceUpgrade python38-psutilUpgrade python38-pip-wheelUpgrade python38-babelUpgrade python38-scipy-debuginfoUpgrade python-psutil-debugsourceUpgrade python38Upgrade python38-lxml-debuginfoUpgrade python38-cryptography-debuginfoUpgrade python38-scipyUpgrade python38-numpy-docUpgrade python38-setuptools-wheelUpgrade python38-cryptographyUpgrade python38-cffiUpgrade python38-psycopg2-debuginfoUpgrade python38-psycopg2-docUpgrade python38-idnaUpgrade python38-pyyaml-debuginfoUpgrade python38-pycparserUpgrade python-psycopg2-debugsourceUpgrade python38-urllib3 | Nov 5, 2020 | Mar 24, 2020 |
| Rocky_linux | — | Upgrade python38-pyyamlUpgrade python38-mod_wsgiUpgrade Cython-debugsourceUpgrade python38-scipyUpgrade python38-numpy-debuginfoUpgrade python38-psutil-debuginfoUpgrade python38-psycopg2Upgrade python-cryptography-debugsourceUpgrade python38-CythonUpgrade python38-cffi-debuginfoUpgrade python38-markupsafeUpgrade python-markupsafe-debugsourceUpgrade PyYAML-debugsourceUpgrade python38-numpyUpgrade python38-pyyaml-debuginfoUpgrade python38-psycopg2-debuginfoUpgrade numpy-debugsourceUpgrade python38-scipy-debuginfoUpgrade python-psycopg2-debugsourceUpgrade python38-cryptographyUpgrade scipy-debugsourceUpgrade python-cffi-debugsourceUpgrade python38-cryptography-debuginfoUpgrade python38-cffiUpgrade python38-markupsafe-debuginfoUpgrade python38-Cython-debuginfoUpgrade python38-psutilUpgrade python-psutil-debugsourceUpgrade python38-psycopg2-docUpgrade python38-numpy-f2pyUpgrade python38-psycopg2-tests | Mar 12, 2024 | Mar 24, 2020 |
| Suse | — | Upgrade python2-pyyamlUpgrade python-pyyamlUpgrade python3-pyyaml | Apr 12, 2020 | Mar 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub