{"id":"GHSA-hjr4-fhgp-23g9","summary":"qlib Deserialization of Untrusted Data vulnerability","details":"This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.","aliases":["CVE-2021-23338","PYSEC-2021-86","SNYK-PYTHON-QLIB-1054635"],"modified":"2024-10-14T18:38:35.640542Z","published":"2022-05-24T17:42:16Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-29T11:02:15Z","nvd_published_at":"2021-02-15T16:15:00Z","cwe_ids":["CWE-502","CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23338"},{"type":"WEB","url":"https://github.com/418sec/huntr/pull/1329"},{"type":"PACKAGE","url":"https://github.com/microsoft/qlib"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyqlib/PYSEC-2021-86.yaml"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-PYQLIB-1085990"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PYTHON-QLIB-1054635"}],"affected":[{"package":{"name":"pyqlib","ecosystem":"PyPI","purl":"pkg:pypi/pyqlib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.0"}]}],"versions":["0.5.0.dev10","0.5.0.dev7","0.5.0.dev8","0.5.0.dev9","0.5.1","0.5.1.dev0","0.6.0","0.6.1","0.6.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hjr4-fhgp-23g9/GHSA-hjr4-fhgp-23g9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}