메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16615

관리자 2017.11.09 04:00 조회 수 : 20

An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLAlchemy before 0.2.2. When processing YAML-Based queries for data, a YAML parser can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16615
번호 제목 글쓴이 날짜 조회 수
167 CVE-2016-0872 관리자 2017.11.09 18
166 CVE-2017-2883 관리자 2017.11.09 18
165 CVE-2017-12703 관리자 2017.08.27 18
164 CVE-2016-5816 관리자 2017.08.27 18
163 CVE-2017-13686 관리자 2017.08.27 18
162 CVE-2017-13669 관리자 2017.08.27 18
161 CVE-2017-11424 관리자 2017.08.27 18
160 CVE-2017-12836 관리자 2017.08.27 18
159 CVE-2017-12137 관리자 2017.08.27 18
158 CVE-2017-0805 (android) 관리자 2017.08.27 18
157 CVE-2017-13137 (formcraft) 관리자 2017.08.27 18
156 CVE-2017-13130 관리자 2017.08.27 18
155 CVE-2017-12786 관리자 2017.08.27 18
154 CVE-2015-3617 관리자 2017.08.27 18
153 CVE-2014-3929 관리자 2017.04.04 18
위로