Junglewise Threat Intelligence

CVE-2019-20477: PYSEC-2020-176 - PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Po

CVE-2019-20477 · Severity: low · CVSS 3.1 · Published 2020-02-19

Technologies: PyYAML (PyPI). Vendors: PyPI.

Executive brief

PyYAML is a widely-used Python library for parsing YAML configuration files and data formats. Versions 5.1 to 5.1.2 allow attackers to execute arbitrary code by providing malicious YAML input to the load() or load_all() functions, due to unsafe deserialization of Python object classes like subprocess.Popen. An attacker with the ability to control YAML input can achieve complete system compromise.

Technical details

PyYAML versions 5.1 through 5.1.2 suffer from unsafe deserialization of untrusted data (CWE-502). The vulnerability exists in the load() and load_all() functions which fail to properly restrict instantiation of arbitrary Python classes during YAML parsing. An attacker can craft a malicious YAML document that deserializes to dangerous classes such as subprocess.Popen, allowing arbitrary command execution. The flaw represents an incomplete fix for the earlier CVE-2017-18342. No authentication or user interaction is required; exploitation occurs whenever an application processes untrusted YAML input via load() or load_all(). This vulnerability was patched in version 5.2.

Affected products

  • PyYAML PyYAML 5.1 through 5.1.2

Timeline

  • 2020-02-19: disclosed
  • 2020: patched: Version 5.2 released

Related threats