CVE-2011-4104

Source
https://cve.org/CVERecord?id=CVE-2011-4104
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2011-4104.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2011-4104
Aliases
Downstream
Withdrawn
2026-01-27T04:10:58Z
Published
2014-10-27T01:55:23Z
Modified
2026-01-27T04:10:58Z
Summary
[none]
Details

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

References

Affected packages