← Back

CVE-2011-4104

nvd nist
Published: Oct 27, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

Affected (1)

1 product
Tastypie
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.9.9

Timeline

No history available yet.