VYPR
Critical severityNVD Advisory· Published Feb 19, 2020· Updated Aug 5, 2024

CVE-2019-20477

CVE-2019-20477

Description

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pyyamlPyPI
>= 5.1, < 5.25.2

Affected products

18

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.