3 ms·
The problem is any YAML loader which supports tags that can name arbitrary classes and have existent classes whose initialization may `eval` the supplied values
by dbenhur 14y ago
The problem is any YAML loader which supports tags that can name arbitrary classes and have existent classes whose initialization may `eval` the supplied values. Ruby is very publicly hurting, but equivalent vulnerabilities exist in other runtimes, such as Perl via [YAML::Syck](http://search.cpan.org/~toddr/YAML-Syck-1.22/lib/YAML/Syck.pm http://search.cpan.org/~toddr/YAML-Syck-1.22/lib/YAML/Syck.p...) or Python via [PyYAML](http://pyyaml.org/wiki/PyYAML http://pyyaml.org/wiki/PyYAML) and [LibYAML](http://pyyaml.org/wiki/LibYAML http://pyyaml.org/wiki/LibYAML). If your language can accept and load untrusted yaml and your language has `eval`, you're probably fucked and just don't know it yet.
- batiste 14y agoThe problem is that YAML is used by Rails & Co as a parser for untrusted user-provided data. It does not matter if there is buggy implementation in Python/Perl if nobody use them. If other framework were using YAML in this fashion, yesterday will be the time to look for security holes in those implementations.