Fixing 32 Arbitrary Code Execution On OpenCTI Project. - #2
Conversation
|
👋 Hello, @SamuelHassine - @DEMON1A has opened a PR to us with a fix for a potential vulnerability in your repository. To view the vulnerability, please refer to the bounty URL in the first comment, above. Ultimately, you get to decide if the fix is 👍 or 👎. If you are happy with the fix, please write a new comment ( If you have any questions or need support, come and join us on our community Discord! @SamuelHassine & @DEMON1A - thank you for your efforts in securing the world’s open source code! 🎉 🔨 Want more security researchers protecting your repository? Stick our badge on your Copy this small code snippet and insert it into your
👇 👇 👇 |
📊 Metadata *
Bounty URL: https://www.huntr.dev/bounties/1-other-lastinfosec
⚙️ Description *
💻 Technical Description *
yaml.FullLoaderAttackers Can Get Code Execution From OpenCTI Project Using a YAML File That Will Inject a Python Code Due To Insecure YAML Processing. In This Case I Fixed This Isssue By Usingyaml.SafeLoaderAnd It Was Really Painful To Edit All Of These 32 Modules.🐛 Proof of Concept (PoC) *
🔗 Relates to...