CVE-2021-38305
Dashboard / Vulnerabilities / CVE-2021-38305
CVE-2021-38305
Published: 9 Aug 2021Last Modified: 9 Jul 2026
Aliases:
Summary:
Details: 23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the eval. When processing the schema, each line is run through Python's eval function to make the validator available. A well-constructed string within the schema rules can execute system commands; thus, by exploiting the vulnerability, an attacker can run arbitrary code on the image that invokes Yamale.
References: https://github.com/23andMe/Yamale/releases/tag/3.0.8, https://github.com/23andMe/Yamale/pull/165
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
