This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-PYTHON-QLIB-1054635 | third party advisory |
https://github.com/418sec/huntr/pull/1329 | exploit third party advisory patch |