CVE-2019-20478
Last modified
CVE-2019-20478 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.. EPSS estimates a 6.59% chance of exploitation in the next 30 days.
Description
In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruamel.Yaml Project | Ruamel.Yaml | <= 0.16.7 |
References
- https://www.exploit-db.com/exploits/47655Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/47655Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-20478?
How severe is CVE-2019-20478?
How do I fix CVE-2019-20478?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-20470An issue was discovered on TK-Star Q90 Junior GPS horloge 3.…7.5
- CVE-2019-20471An issue was discovered on TK-Star Q90 Junior GPS horloge 3.…7.8
- CVE-2019-20472An issue was discovered on One2Track 2019-12-08 devices. Any…6.2
- CVE-2019-20473An issue was discovered on TK-Star Q90 Junior GPS horloge 3.…6.8
- CVE-2019-20474An issue was discovered in Zoho ManageEngine Remote Access P…4.3
- CVE-2019-20477PyYAML 5.1 through 5.1.2 has insufficient restrictions on th…9.8
- CVE-2019-20479A flaw was found in mod_auth_openidc before version 2.4.1. A…6.1
- CVE-2019-20480In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious w…8.8
- CVE-2019-20481In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password …9.8
- CVE-2019-20483An issue was discovered in Viki Vera 4.9.1.26180. An attacke…5.4
- CVE-2019-20484An issue was discovered in Viki Vera 4.9.1.26180. A user wit…8.1
- CVE-2019-20485qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the ho…5.7
Are you affected by CVE-2019-20478?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
