CVE-2019-10135
Dashboard / Vulnerabilities / CVE-2019-10135
CVE-2019-10135
Published: 11 Jul 2019Last Modified: 8 Jul 2026
Summary:
Details: A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.
References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10135, https://github.com/containerbuildsystem/osbs-client/pull/865
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- bd0523ee69a40134053ff4264dcd7273ae282281
Affected versions
0.56
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
