PoC Index

CVE-2021-24040

CRITICAL 9.8EPSS 17.4%

Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
17.35% chance of exploitation in the next 30 days, 97th percentile
Published
2021-09-10
Updated
2024-08-03

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related