A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python38-cffiUpgrade python38-psycopg2-docUpgrade python38-psycopg2-testsUpgrade python38-pytzUpgrade python38-asn1cryptoUpgrade python38-idnaUpgrade python38-CythonUpgrade python38-pycparserUpgrade python38-requestsUpgrade python38-pysocksUpgrade python38-cryptographyUpgrade python38-scipyUpgrade python38-markupsafeUpgrade python38-mod_wsgiUpgrade python38-psycopg2Upgrade python38-chardet | May 4, 2022 | Mar 24, 2020 |
| Alpine Linux | — | Upgrade py3-yaml | Aug 22, 2024 | Mar 24, 2020 |
| Centos_linux | — | Upgrade python38-lxml-debuginfoUpgrade python38-testUpgrade python38-plyUpgrade python38-psycopg2-debuginfoUpgrade python38-pyyaml-debuginfoUpgrade python38-chardetUpgrade python38-PyMySQLUpgrade python38-scipy-debuginfoUpgrade python38-numpyUpgrade python-cffi-debugsourceUpgrade python38-scipyUpgrade python38-debugsourceUpgrade python38-libsUpgrade python38-cryptographyUpgrade python38Upgrade python-psutil-debugsourceUpgrade python38-pipUpgrade python38-numpy-debuginfoUpgrade python38-numpy-docUpgrade scipy-debugsourceUpgrade python38-idleUpgrade python38-pycparserUpgrade python38-mod_wsgiUpgrade python38-CythonUpgrade python38-setuptools-wheelUpgrade python38-idnaUpgrade python38-sixUpgrade python38-urllib3Upgrade python38-cffiUpgrade python38-psycopg2-testsUpgrade python38-markupsafeUpgrade PyYAML-debugsourceUpgrade python38-psutilUpgrade python38-pip-wheelUpgrade python-lxml-debugsourceUpgrade python38-babelUpgrade python38-pysocksUpgrade numpy-debugsourceUpgrade python38-wheelUpgrade python38-psutil-debuginfoUpgrade python38-tkinterUpgrade python38-cryptography-debuginfoUpgrade python38-lxmlUpgrade python38-markupsafe-debuginfoUpgrade python38-debuginfoUpgrade python38-Cython-debuginfoUpgrade python38-pyyamlUpgrade python38-pytzUpgrade python-markupsafe-debugsourceUpgrade Cython-debugsourceUpgrade python38-rpm-macrosUpgrade python38-develUpgrade python38-asn1cryptoUpgrade python38-psycopg2-docUpgrade python38-jinja2Upgrade python38-numpy-f2pyUpgrade python38-debugUpgrade python38-cffi-debuginfoUpgrade python38-requestsUpgrade python-cryptography-debugsourceUpgrade python38-wheel-wheelUpgrade python38-psycopg2Upgrade python-psycopg2-debugsourceUpgrade python38-setuptools | Nov 5, 2020 | Mar 24, 2020 |
| Debian | — | Upgrade pyyaml | Jul 30, 2024 | Mar 24, 2020 |
| Freebsd | — | Upgrade py36-yamlUpgrade py38-yamlUpgrade py37-yamlUpgrade py35-yamlUpgrade py27-yaml | Apr 28, 2020 | Apr 27, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Jul 20, 2021 | Mar 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-pyyamlUpgrade python2-pyyaml | Jul 31, 2020 | Mar 24, 2020 |
| Oracle Solaris | — | Upgrade library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-37 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-39 to version 5.4.1-11.4.33.0.1.94.0 on Solaris 11.4Upgrade library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-27 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4 | Jan 19, 2021 | Mar 24, 2020 |
| Oracle_linux | — | Upgrade python38-chardetUpgrade python38-idleUpgrade python38-requestsUpgrade python38-cryptographyUpgrade python38-lxmlUpgrade python38-tkinterUpgrade python38-scipyUpgrade python38-pip-wheelUpgrade python38-pyyamlUpgrade python38-urllib3Upgrade python38-jinja2Upgrade python38Upgrade python38-markupsafeUpgrade python38-mod_wsgiUpgrade python38-develUpgrade python38-plyUpgrade python38-babelUpgrade python38-pysocksUpgrade python38-wheel-wheelUpgrade python38-setuptoolsUpgrade python38-sixUpgrade python38-numpyUpgrade python38-debugUpgrade python38-psycopg2Upgrade python38-psycopg2-testsUpgrade python38-cffiUpgrade python38-CythonUpgrade python38-libsUpgrade python38-psycopg2-docUpgrade python38-asn1cryptoUpgrade python38-testUpgrade python38-numpy-f2pyUpgrade python38-pytzUpgrade python38-setuptools-wheelUpgrade python38-psutilUpgrade python38-pycparserUpgrade python38-pipUpgrade python38-PyMySQLUpgrade python38-idnaUpgrade python38-rpm-macrosUpgrade python38-wheelUpgrade python38-numpy-doc | Jul 22, 2024 | Mar 2, 2020 |
| Redhat_linux | — | Upgrade python38-pip-wheelUpgrade python38-pycparserUpgrade python38-psycopg2-testsUpgrade python38-testUpgrade python38-libsUpgrade python-cffi-debugsourceUpgrade python38-sixUpgrade python38-pyyaml-debuginfoUpgrade python38-psycopg2-debuginfoUpgrade python38-psutilUpgrade python38-Cython-debuginfoUpgrade python38-idnaUpgrade python38-debugsourceUpgrade python38-urllib3Upgrade python38-cffiUpgrade python38Upgrade python38-numpyUpgrade python38-cryptography-debuginfoUpgrade python38-babelUpgrade python38-chardetUpgrade python38-scipyUpgrade python38-jinja2Upgrade python38-lxml-debuginfoUpgrade scipy-debugsourceUpgrade python-psycopg2-debugsourceUpgrade numpy-debugsourceUpgrade python38-plyUpgrade python38-setuptools-wheelUpgrade python38-numpy-docUpgrade python38-cryptographyUpgrade python38-scipy-debuginfoUpgrade python38-psycopg2-docUpgrade python-lxml-debugsourceUpgrade python-psutil-debugsourceUpgrade python38-mod_wsgiUpgrade python38-pipUpgrade python38-tkinterUpgrade python38-markupsafeUpgrade python38-asn1cryptoUpgrade Cython-debugsourceUpgrade python38-markupsafe-debuginfoUpgrade python38-numpy-debuginfoUpgrade python38-psycopg2Upgrade python38-idleUpgrade python38-requestsUpgrade python38-CythonUpgrade python38-pysocksUpgrade python38-develUpgrade python38-cffi-debuginfoUpgrade python38-debuginfoUpgrade python38-lxmlUpgrade PyYAML-debugsourceUpgrade python38-PyMySQLUpgrade python38-wheel-wheelUpgrade python38-pytzUpgrade python-cryptography-debugsourceUpgrade python-markupsafe-debugsourceUpgrade python38-numpy-f2pyUpgrade python38-rpm-macrosUpgrade python38-wheelUpgrade python38-setuptoolsUpgrade python38-psutil-debuginfoUpgrade python38-pyyamlUpgrade python38-debug | Nov 5, 2020 | Mar 24, 2020 |
| Rocky_linux | — | Upgrade python38-cryptography-debuginfoUpgrade python38-cryptographyUpgrade python38-markupsafe-debuginfoUpgrade python-cffi-debugsourceUpgrade python38-cffiUpgrade python38-psycopg2-testsUpgrade python38-numpyUpgrade python-psycopg2-debugsourceUpgrade python38-Cython-debuginfoUpgrade python38-pyyaml-debuginfoUpgrade python38-numpy-f2pyUpgrade scipy-debugsourceUpgrade python38-scipy-debuginfoUpgrade python-psutil-debugsourceUpgrade numpy-debugsourceUpgrade python38-psutilUpgrade python38-psycopg2-debuginfoUpgrade python38-psycopg2-docUpgrade python38-numpy-debuginfoUpgrade python38-scipyUpgrade python38-pyyamlUpgrade python-markupsafe-debugsourceUpgrade python38-psutil-debuginfoUpgrade python38-markupsafeUpgrade PyYAML-debugsourceUpgrade python38-CythonUpgrade Cython-debugsourceUpgrade python-cryptography-debugsourceUpgrade python38-mod_wsgiUpgrade python38-psycopg2Upgrade python38-cffi-debuginfo | Mar 12, 2024 | Mar 24, 2020 |
| Suse | — | Upgrade python3-pyyamlUpgrade python2-pyyamlUpgrade python-pyyaml | Apr 12, 2020 | Mar 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub