Safety vulnerability ID: 36768
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Sqla_yaml_fixtures 0.9.1 is affected by CVE-2019-3575: It allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
https://github.com/schettino72/sqla_yaml_fixtures/issues/20
Latest version: 1.1.0
Load YAML data fixtures for SQLAlchemy
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
MISC:https://github.com/schettino72/sqla_yaml_fixtures/issues/20: https://github.com/schettino72/sqla_yaml_fixtures/issues/20
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application