Junglewise Threat Intelligence

CVE-2019-3575: PYSEC-2019-122 - Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.

CVE-2019-3575 · Severity: low · CVSS 3.1 · Published 2019-01-03

Vendors: PyPI.

Executive brief

sqla-yaml-fixtures is a Python library that loads test data from YAML fixture files into SQL databases. The library fails to safely deserialize YAML input, allowing an authenticated user to execute arbitrary Python code by crafting malicious YAML content in fixture files. This enables complete system compromise including data theft, malware installation, and service disruption.

Technical details

The vulnerability is a code injection flaw (CWE-94) in the sqla_yaml_fixtures.load() method, which uses unsafe YAML deserialization. Versions up to 0.9.1 accept untrusted YAML in the fixture_text argument without proper sanitization, allowing attackers to instantiate arbitrary Python objects such as os.system via YAML tags like "!!python/object/apply". An authenticated local user can invoke the vulnerable method with malicious YAML to execute system commands with the application's privileges. The attack requires local access and prior authentication but no additional user interaction. Patch status: unknown from provided advisory; users should check for updates or use safe YAML loading (yaml.safe_load).

Affected products

  • sqla-yaml-fixtures sqla-yaml-fixtures 0 through 0.9.1

Timeline

  • 2019-01-04: disclosed: OSV advisory published

References

Related threats