Django Tastypie Improper Deserialization of YAML Data
Critical severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Description
Published by the National Vulnerability Database
Oct 27, 2014
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jan 12, 2024
Last updated
Sep 16, 2024
The
from_yaml
method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.References