peter bassill · operator
$ cve CVE-2020-1747 JSON

CVE-2020-1747

9.8
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.44% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-03-24
Last modified2026-06-17

Affected (4)

VendorProduct
fedoraprojectfedora
opensuseleap
oraclecommunications cloud native core network function cloud native environment
pyyamlpyyaml

References

→ the Explorer  ·  watch your stack  ·  NVD