Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Django Tastypie 输入验证漏洞
Vulnerability Description
Django是Django软件基金会的一套基于Python语言的开源Web应用框架。Django Tastypie是其中的一个Web服务API框架。 Django Tastypie 0.9.10之前版本的serializers.py脚本中的from_yaml方法存在安全漏洞,该漏洞源于程序没有正确反序列化YAML数据。远程攻击者可利用该漏洞执行任意Python代码。
CVSS Information
N/A
Vulnerability Type
N/A