CVE-2019-10135
11.07.2019, 19:15
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.Enginsight
| Vendor | Product | Version |
|---|---|---|
| osbs-client_project | osbs-client | 0.46 ≤ 𝑥 < 0.56.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration