PT-2019-11591 · Red Hat · Osbs-Client

Martin Bašti

+1

·

Published

2019-07-11

·

Updated

2022-11-07

·

CVE-2019-10135

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: osbs-client versions 0.46 through 0.56.0
Description: A flaw was found in the yaml.load() function, allowing insecure use that enables loading of suspicious objects for code execution via parsing of malicious YAML files.
Recommendations: For osbs-client versions 0.46 through 0.56.0, update to version 0.56.1 or later to resolve the issue. As a temporary workaround, consider disabling the use of the yaml.load() function until a patch is available. Restrict access to parsing YAML files to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2019-10135

Affected Products

Osbs-Client