Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2017-20285— YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes

Quick assessment

Affected
CVE-2017-20285
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Perl 的 YAML 模块在 1.30 版本之前存在一个安全漏洞,允许通过加载的 YAML 文档触发任意类的 DESTROY 方法。 当使用 标签时,YAML 解析器会将一个哈希结构绑定(bless)到指定名称的类中。文档中提供的数据将作为该对象的字段内容。当该对象离开其作用域时,Perl 会自动调用其 DESTROY 方法。 DESTROY 方法的具体行为取决于当前 Perl 进程中已加载的类。例如,在核心 Perl 模块 File::Temp::Dir 中,DESTROY 方法可能用于删除 YAML 文档中所

AI Predicted 7.5 Difficulty: Easy

I. Basic Information for CVE-2017-20285

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
Source: CVE Program / CVE List V5
Vulnerability Description
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 1.30 -

II. Public POCs for CVE-2017-20285

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-20285

请登录查看更多情报信息。

Other References for CVE-2017-20285 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2017-20285

No comments yet


Leave a comment