PT-2017-14546 · Django · Django Make App
Joel
·
Published
2017-11-10
·
Updated
2019-12-11
·
CVE-2017-16764
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
django make app version 0.1.3
Description
The issue concerns the YAML parsing functionality in the
read yaml file method within io utils.py. This allows a YAML parser to execute arbitrary Python commands, resulting in command execution. An attacker can exploit this by inserting Python code into loaded YAML files.Recommendations
For django make app version 0.1.3, consider disabling the
read yaml file method in io utils.py until a patch is available to prevent the execution of arbitrary Python commands. Restrict the loading of YAML files to trusted sources to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django Make App