Junglewise Threat Intelligence

PYSEC-2019-52 - Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.

Severity: info · Published 2019-01-03

Vendors: PyPI.

Executive brief

Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.

Affected products

  • PyPI sqla-yaml-fixtures

Related threats