CVE-2021-27213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
14/02/2021
Last modified:
18/02/2021

Description

config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pystemon_project:pystemon:*:*:*:*:*:*:*:* 2021-02-13 (excluding)