Safety vulnerability ID: 25794
The information on this page was manually curated by our Cybersecurity Intelligence Team.
The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.
Latest version: 0.15.0
A flexible & capable API layer for Django.
The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application