emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| django-piston(PyPI) | 0.2.0 | 0.2.2.1 | N/A |
CVSS Metrics