CVE-2021-23338

Description

This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

Risk Information

Base Score
7.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.852

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-23338 are fixed in Python-pyqlib 0.7.0Windows
Vulnerabilities CVE-2021-23338 are fixed in Python-pyqlib for linux 0.7.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234