CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Oracle Pyyaml2Communications Cloud Native Core Network Function Cloud Native Environment PyyamlNov 21, 2024 Feb 9, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader...Show more |
4Fedoraproject OpensuseOracle+1 more4Communications Cloud Native Core Network Function Cloud Native Environment FedoraLeap+1 moreNov 21, 2024 Mar 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoade...Show more |
2Fedoraproject Pyyaml2Fedora PyyamlNov 21, 2024 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an i...Show more |
2Fedoraproject Pyyaml2Fedora PyyamlNov 21, 2024 Jun 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibi...Show more |