PYSEC-2021-334

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/parlai/PYSEC-2021-334.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2021-334
Aliases
Published
2021-09-10T23:15:00Z
Modified
2023-11-01T04:54:44.487261Z
Summary
[none]
Details

parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. This security bug is patched by avoiding unsafe loader users should update to version above v1.1.0. If upgrading is not possible then users can change the Loader used to SafeLoader as a workaround. See commit 507d066ef432ea27d3e201da08009872a2f37725 for details.

References

Affected packages

PyPI / parlai

Package

Affected ranges

Type
GIT
Repo
https://github.com/facebookresearch/ParlAI
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.0

Affected versions

0.*

0.1.20200409
0.1.20200416
0.1.20200610
0.1.20200713
0.1.20200716
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.10.0

1.*

1.0.0