Code injection in ymlref
Critical severity
GitHub Reviewed
Published
Dec 19, 2018
to the GitHub Advisory Database
•
Updated Nov 19, 2024
Description
Published to the GitHub Advisory Database
Dec 19, 2018
Reviewed
Jun 16, 2020
Last updated
Nov 19, 2024
ymlref is a library that allows to load Yaml documents and resolve JSON-pointer references inside them. ymlref versions up to 0.1.1 allow code injection.
References