9.8
CVE-2017-16618
- EPSS 4.47%
- Veröffentlicht 08.11.2017 03:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
An exploitable vulnerability exists in the YAML loading functionality of util.py in OwlMixin before 2.0.0a12. A "Load YAML" string or file (aka load_yaml or load_yamlf) can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Owlmixin Project ≫ Owlmixin Version < 2.0.0
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha1
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha10
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha11
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha2
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha3
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha4
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha5
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha6
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha7
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha8
Owlmixin Project ≫ Owlmixin Version 2.0.0 Update alpha9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.47% | 0.905 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
https://github.com/tadashi-aikawa/owlmixin/commit/5d0575303f6df869a515ced4285f24ba721e0d4e
https://github.com/tadashi-aikawa/owlmixin/issues/12
https://joel-malwarebenchmark.github.io/blog/2017/11/08/cve-2017-16618-convert-through-owlmixin/