CVE-2019-10135
Severity CVSS v4.0:
Pending analysis
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
11/07/2019
Last modified:
07/11/2022
Description
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:osbs-client_project:osbs-client:*:*:*:*:*:*:*:* | 0.46 (including) | 0.56.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page