python-ruamel-yaml: code execution through load() method with an untrusted argument
Published Feb 19, 2020
9.8
CRITICALCVSS 3.1
EPSS 6.75%
Description
In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.
Affected products
No data.
- ≤ 0.16.7
No data.
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-curator5
Not affected
Red Hat OpenShift Container Platform 3.11
python-openshift
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-curator5
Not affected
Red Hat OpenShift Container Platform 4
python-openshift
Will not fix
Red Hat OpenStack Platform 15 (Stein)
python-ruamel-yaml
Out of support scope
Red Hat OpenStack Platform 16 (Train)
python-ruamel-yaml
Will not fix
Red Hat Storage 3
python-ruamel-yaml
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-curator5 | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | python-openshift | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-curator5 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | python-openshift | Will not fix | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-ruamel-yaml | Out of support scope | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-ruamel-yaml | Will not fix | n/a |
| Red Hat Storage 3 | python-ruamel-yaml | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While the openshift-logging-curator5-container contains the vulnerable code, and method call, it only uses it to load a configuration file, which can be considered trusted data. Therefore this component of OpenShift Container Platform is not affected. The python-openshift the dependency of OpenShift Container Platform is only used in a deprecated and unused build script (that is removed in later versions), and does not pose a risk to consumers of this library. Therefore it will not be fixed.
Red Hat mitigation
Use the 'safe_load' method in place of 'load' if loading untrusted data. Alternatively use: yaml=YAML(typ='safe') yaml.load() Reference: https://yaml.readthedocs.io/en/latest/basicuse.html
References (6)
- https://access.redhat.com/security/cve/CVE-2019-20478 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1808088 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11022 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20478
- https://www.cve.org/CVERecord?id=CVE-2019-20478
- https://www.exploit-db.com/exploits/47655 x_refsource_MISCThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20478 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1808088 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11022 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20478 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-20478 | ||
| https://www.exploit-db.com/exploits/47655 | x_refsource_MISCThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.