GHSA-j28r-j54m-gpc4
Dashboard / Vulnerabilities / GHSA-j28r-j54m-gpc4
GHSA-j28r-j54m-gpc4
Summary: Code Injection in SLO Generator
Details: SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past https://github.com/google/slo-generator/pull/173
References: https://nvd.nist.gov/vuln/detail/CVE-2021-22557, https://github.com/google/slo-generator/pull/173, https://github.com/google/slo-generator/commit/36318beab1b85d14bb860e45bea186b184690d5d, https://github.com/google/slo-generator/releases/tag/v2.0.1, https://github.com/pypa/advisory-database/tree/main/vulns/slo-generator/PYSEC-2021-429.yaml, ://github.com/google/slo-generator, http://packetstormsecurity.com/files/164426/Google-SLO-Generator-2.0.0-Code-Execution.html
Affected packages
Package
Name: slo-generator
Purl: pkg:pypi/slo-generator
Affected ranges
Type: ECOSYSTEM
Events:
