A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python38-chardetUpgrade python38-markupsafeUpgrade python38-cryptographyUpgrade python38-psycopg2Upgrade python38-scipyUpgrade python38-pysocksUpgrade python38-mod_wsgiUpgrade python38-pytzUpgrade python38-cffiUpgrade python38-asn1cryptoUpgrade python38-psycopg2-testsUpgrade python38-CythonUpgrade python38-psycopg2-docUpgrade python38-pycparserUpgrade python38-idnaUpgrade python38-requests | May 4, 2022 | Mar 24, 2020 |
| Alpine Linux | — | Upgrade py3-yaml | Aug 22, 2024 | Mar 24, 2020 |
| Centos_linux | — | Upgrade python38-pycparserUpgrade python38-idleUpgrade python38-lxml-debuginfoUpgrade python38-idnaUpgrade scipy-debugsourceUpgrade python38-numpy-docUpgrade python38-libsUpgrade python38-sixUpgrade python38-urllib3Upgrade python38-pipUpgrade python38-chardetUpgrade python38-setuptools-wheelUpgrade python38Upgrade python38-CythonUpgrade python38-scipy-debuginfoUpgrade python38-numpy-debuginfoUpgrade python38-scipyUpgrade python-psutil-debugsourceUpgrade python38-pip-wheelUpgrade python38-mod_wsgiUpgrade python-cffi-debugsourceUpgrade python38-markupsafeUpgrade python38-psycopg2-testsUpgrade python38-numpyUpgrade python38-PyMySQLUpgrade python38-debugsourceUpgrade python38-psutilUpgrade python38-cryptographyUpgrade python38-plyUpgrade python38-testUpgrade python38-babelUpgrade PyYAML-debugsourceUpgrade python38-pysocksUpgrade python38-pyyaml-debuginfoUpgrade python38-psycopg2-debuginfoUpgrade python-lxml-debugsourceUpgrade python38-cffiUpgrade python38-Cython-debuginfoUpgrade python38-psycopg2-docUpgrade python38-pytzUpgrade python-markupsafe-debugsourceUpgrade python38-jinja2Upgrade python38-tkinterUpgrade python38-pyyamlUpgrade python38-psutil-debuginfoUpgrade python38-markupsafe-debuginfoUpgrade python38-debuginfoUpgrade python38-requestsUpgrade python38-psycopg2Upgrade python38-cryptography-debuginfoUpgrade python38-setuptoolsUpgrade python38-rpm-macrosUpgrade python38-develUpgrade python-cryptography-debugsourceUpgrade Cython-debugsourceUpgrade python38-wheel-wheelUpgrade python38-lxmlUpgrade python-psycopg2-debugsourceUpgrade python38-cffi-debuginfoUpgrade python38-debugUpgrade python38-wheelUpgrade python38-numpy-f2pyUpgrade numpy-debugsourceUpgrade python38-asn1crypto | Nov 5, 2020 | Mar 24, 2020 |
| Debian | — | Upgrade pyyaml | Jul 30, 2024 | Mar 24, 2020 |
| Freebsd | — | Upgrade py35-yamlUpgrade py37-yamlUpgrade py27-yamlUpgrade py38-yamlUpgrade py36-yaml | Apr 28, 2020 | Apr 27, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Jul 20, 2021 | Mar 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-pyyamlUpgrade python2-pyyaml | Jul 31, 2020 | Mar 24, 2020 |
| Oracle Solaris | — | Upgrade library/python/pyyaml-37 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-39 to version 5.4.1-11.4.33.0.1.94.0 on Solaris 11.4Upgrade legacy/library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade legacy/library/python/pyyaml-35 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-27 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml-34 to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4Upgrade library/python/pyyaml to version 5.3.1-11.4.23.0.1.69.1 on Solaris 11.4 | Jan 19, 2021 | Mar 24, 2020 |
| Oracle_linux | — | Upgrade python38-CythonUpgrade python38-debugUpgrade python38-cffiUpgrade python38-idnaUpgrade python38-numpy-docUpgrade python38-psycopg2Upgrade python38-PyMySQLUpgrade python38-pipUpgrade python38-asn1cryptoUpgrade python38-psycopg2-docUpgrade python38-pytzUpgrade python38-wheelUpgrade python38-psutilUpgrade python38-pycparserUpgrade python38-libsUpgrade python38-psycopg2-testsUpgrade python38-numpy-f2pyUpgrade python38-sixUpgrade python38-numpyUpgrade python38-setuptools-wheelUpgrade python38-testUpgrade python38-rpm-macrosUpgrade python38-develUpgrade python38-markupsafeUpgrade python38-babelUpgrade python38-plyUpgrade python38-pysocksUpgrade python38-mod_wsgiUpgrade python38-setuptoolsUpgrade python38-lxmlUpgrade python38-tkinterUpgrade python38-requestsUpgrade python38-wheel-wheelUpgrade python38-jinja2Upgrade python38-idleUpgrade python38-chardetUpgrade python38-pyyamlUpgrade python38-urllib3Upgrade python38-pip-wheelUpgrade python38Upgrade python38-cryptographyUpgrade python38-scipy | Jul 22, 2024 | Mar 2, 2020 |
| Redhat_linux | — | Upgrade python38-debugUpgrade PyYAML-debugsourceUpgrade python38-cffi-debuginfoUpgrade python38-develUpgrade python38-numpy-f2pyUpgrade Cython-debugsourceUpgrade python38-idleUpgrade python38-lxmlUpgrade python38-pipUpgrade python38-asn1cryptoUpgrade python38-markupsafe-debuginfoUpgrade python38-CythonUpgrade python38-markupsafeUpgrade python38-wheel-wheelUpgrade python-markupsafe-debugsourceUpgrade python38-pysocksUpgrade python38-debuginfoUpgrade python38-PyMySQLUpgrade python38-pytzUpgrade python38-setuptoolsUpgrade python38-tkinterUpgrade python38-psutil-debuginfoUpgrade python38-rpm-macrosUpgrade python-cryptography-debugsourceUpgrade python38-mod_wsgiUpgrade python38-pyyamlUpgrade python38-wheelUpgrade python38-numpy-debuginfoUpgrade python38-psycopg2Upgrade python38-requestsUpgrade python38-babelUpgrade python38-cffiUpgrade python38-testUpgrade python38-pycparserUpgrade python-psycopg2-debugsourceUpgrade python38-scipyUpgrade python38-debugsourceUpgrade python38-urllib3Upgrade python38-pip-wheelUpgrade python38-chardetUpgrade python38-Cython-debuginfoUpgrade python38-scipy-debuginfoUpgrade python-lxml-debugsourceUpgrade python38-cryptographyUpgrade python38-psycopg2-docUpgrade python38-setuptools-wheelUpgrade python38-numpy-docUpgrade python38Upgrade python-cffi-debugsourceUpgrade python38-plyUpgrade python38-jinja2Upgrade numpy-debugsourceUpgrade python38-lxml-debuginfoUpgrade python-psutil-debugsourceUpgrade python38-numpyUpgrade python38-cryptography-debuginfoUpgrade scipy-debugsourceUpgrade python38-libsUpgrade python38-psycopg2-testsUpgrade python38-sixUpgrade python38-psutilUpgrade python38-idnaUpgrade python38-pyyaml-debuginfoUpgrade python38-psycopg2-debuginfo | Nov 5, 2020 | Mar 24, 2020 |
| Rocky_linux | — | Upgrade python38-pyyaml-debuginfoUpgrade python38-numpy-f2pyUpgrade python38-psycopg2-debuginfoUpgrade python38-psycopg2-docUpgrade scipy-debugsourceUpgrade numpy-debugsourceUpgrade python-cffi-debugsourceUpgrade python38-cryptography-debuginfoUpgrade python38-cffiUpgrade python38-cryptographyUpgrade python38-psutilUpgrade python-psutil-debugsourceUpgrade python38-numpyUpgrade python38-markupsafe-debuginfoUpgrade python38-psycopg2-testsUpgrade python38-Cython-debuginfoUpgrade python-psycopg2-debugsourceUpgrade python38-markupsafeUpgrade python38-psutil-debuginfoUpgrade python38-CythonUpgrade python38-scipyUpgrade Cython-debugsourceUpgrade python38-pyyamlUpgrade python-markupsafe-debugsourceUpgrade python38-mod_wsgiUpgrade python-cryptography-debugsourceUpgrade python38-psycopg2Upgrade python38-cffi-debuginfoUpgrade python38-numpy-debuginfoUpgrade PyYAML-debugsourceUpgrade python38-scipy-debuginfo | Mar 12, 2024 | Mar 24, 2020 |
| Suse | — | Upgrade python2-pyyamlUpgrade python-pyyamlUpgrade python3-pyyaml | Apr 12, 2020 | Mar 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub