CVE-2019-10135

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
11/07/2019
Last modified:
07/11/2022

Description

A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osbs-client_project:osbs-client:*:*:*:*:*:*:*:* 0.46 (including) 0.56.1 (excluding)