Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrading pyyaml to >= 5.4 #3963

Closed
henry54809 opened this issue Oct 18, 2021 · 2 comments
Closed

Upgrading pyyaml to >= 5.4 #3963

henry54809 opened this issue Oct 18, 2021 · 2 comments

Comments

@henry54809
Copy link

Hi,
There is a critical vulnerability for pyyaml < 5.4 that allows arbitrary code execution when processing untrusted yaml file. For more details, please see here: https://nvd.nist.gov/vuln/detail/CVE-2020-14343

@gizmoguy
Copy link
Member

gizmoguy commented Nov 9, 2021

I got #3962 merged which should address this.

@gizmoguy gizmoguy closed this as completed Nov 9, 2021
@henry54809
Copy link
Author

Thanks for updating this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants