PYSEC-2021-334

    Dashboard / Vulnerabilities / PYSEC-2021-334

    PYSEC-2021-334

    Published: 10 Sept 2021Last Modified: 8 Nov 2023

    Summary:

    Details: parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. This security bug is patched by avoiding unsafe loader users should update to version above v1.1.0. If upgrading is not possible then users can change the Loader used to SafeLoader as a workaround. See commit 507d066ef432ea27d3e201da08009872a2f37725 for details.

    Affected packages

    Package

    Name: parlai

    Purl: pkg:pypi/parlai

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    0.1.20200409
    0.1.20200416
    0.1.20200610
    0.1.20200713
    0.1.20200716

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2021-334 | CVE-DB