← Back

CVE-2011-4103

nvd nist
Published: Oct 27, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

Affected (1)

1 product
Piston
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.2.2.0

References (10)

Timeline

No history available yet.