CVE-2011-4103

Description

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.821

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2011-4103 are fixed in Python-django-piston 0.2.2.1Windows
Vulnerabilities CVE-2011-4103 are fixed in Python-django-piston for linux 0.2.2.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234