Executive brief
PyYAML is a widely-used Python library for parsing YAML configuration files and data formats. Versions 5.1 to 5.1.2 allow attackers to execute arbitrary code by providing malicious YAML input to the load() or load_all() functions, due to unsafe deserialization of Python object classes like subprocess.Popen. An attacker with the ability to control YAML input can achieve complete system compromise.
Technical details
PyYAML versions 5.1 through 5.1.2 suffer from unsafe deserialization of untrusted data (CWE-502). The vulnerability exists in the load() and load_all() functions which fail to properly restrict instantiation of arbitrary Python classes during YAML parsing. An attacker can craft a malicious YAML document that deserializes to dangerous classes such as subprocess.Popen, allowing arbitrary command execution. The flaw represents an incomplete fix for the earlier CVE-2017-18342. No authentication or user interaction is required; exploitation occurs whenever an application processes untrusted YAML input via load() or load_all(). This vulnerability was patched in version 5.2.
Affected products
- PyYAML PyYAML 5.1 through 5.1.2
Timeline
- 2020-02-19: disclosed
- 2020: patched: Version 5.2 released