MEDIUM
GHSA-mwgj-7x7j-6966
Deserialization of Untrusted Data in ParlAI
Quick fix
GHSA-mwgj-7x7j-6966 — parlai: upgrade to the fixed version with the command below.
pip install --upgrade 'parlai>=1.1.0'Details
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/facebookresearch/ParlAI/security/advisories/GHSA-m87f-9fvv-2mgg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-24040[ADVISORY]
- https://github.com/facebookresearch/ParlAI/pull/3402[WEB]
- https://github.com/facebookresearch/ParlAI/pull/3429[WEB]
- https://github.com/facebookresearch/ParlAI/commit/4374fa2aba383db6526ab36e939eb1cf8ef99879[WEB]
- https://github.com/facebookresearch/ParlAI[PACKAGE]
- https://github.com/facebookresearch/ParlAI/releases/tag/v1.1.0[WEB]
- http://packetstormsecurity.com/files/164136/Facebook-ParlAI-1.0.0-Code-Execution-Deserialization.html[WEB]