Safety vulnerability ID: 36976
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execution.
Latest version: 0.8.1.post1
Python package for configuring a python package
An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execution.
MISC:https://github.com/pytroll/donfig/commits/master: https://github.com/pytroll/donfig/commits/master
MISC:https://github.com/pytroll/donfig/issues/5: https://github.com/pytroll/donfig/issues/5
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application