PT-2021-15141 · Google · Slo Generator

Cimihan123

+1

·

Published

2021-10-04

·

Updated

2022-10-25

·

CVE-2021-22557

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SLO Generator versions prior to the version including https://github.com/google/slo-generator/pull/173
Description The SLO generator has an issue where it allows for the loading of YAML files. If these files are crafted in a specific format, they can enable code execution within the context of the SLO Generator.
Recommendations Upgrade SLO Generator past the version including https://github.com/google/slo-generator/pull/173. As a temporary workaround, consider restricting the loading of YAML files or ensuring they are thoroughly validated before use to minimize the risk of exploitation.

Exploit

Fix

Code Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-22557
GHSA-J28R-J54M-GPC4
PYSEC-2021-429

Affected Products

Slo Generator