GHSA-h72c-w3q3-55qq
CRITICALCVE-2020-13388An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safeload is not used.
- Affected
- < 2.3
- Fixed in
- 2.3
- Weakness
- CWE-78
- Published
- 2021-06-02
- Source
- github