PT-2019-11591 · Red Hat · Osbs-Client
Martin Bašti
+1
·
Published
2019-07-11
·
Updated
2022-11-07
·
CVE-2019-10135
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
osbs-client versions 0.46 through 0.56.0
Description:
A flaw was found in the
yaml.load() function, allowing insecure use that enables loading of suspicious objects for code execution via parsing of malicious YAML files.Recommendations:
For osbs-client versions 0.46 through 0.56.0, update to version 0.56.1 or later to resolve the issue. As a temporary workaround, consider disabling the use of the
yaml.load() function until a patch is available. Restrict access to parsing YAML files to minimize the risk of exploitation.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Osbs-Client