Security Advisory

CVE-2019-10135

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-11 00:00:00
Last updated 2024-08-04 22:10:09
Assigner redhat
CVSS score 7.2
State PUBLISHED

Description

A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.