logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-13388

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-13388

Description:
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.
Last updated date:
03/03/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
05/28/2020
Reference url to background

https://joel-malwarebenchmark.github.io

Type:
exploit
Confidence:
HIGH
Date of publishing:
03/03/2023
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy