CVE-2019-20477
19.02.2020, 04:15
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.Enginsight
Vendor | Product | Version |
---|---|---|
pyyaml | pyyaml | 5.1 ≤ 𝑥 ≤ 5.1.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References