A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.
{ "source": "CPE_RANGE", "cpe": "cpe:2.3:a:osbs-client_project:osbs-client:*:*:*:*:*:*:*:*", "extracted_events": [ { "introduced": "0.46" }, { "fixed": "0.56.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10135.json"