Code injection in ymlref
Critical severity
GitHub Reviewed
Published
Dec 19, 2018
to the GitHub Advisory Database
•
Updated Aug 16, 2023
Description
Published to the GitHub Advisory Database
Dec 19, 2018
Reviewed
Jun 16, 2020
Last updated
Aug 16, 2023
ymlref is a library that allows to load Yaml documents and resolve JSON-pointer references inside them. ymlref versions up to 0.1.1 allow code injection.
References