Do not use insecure YAML deserialization
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
ID: python-security/ruamel-unsafe-yaml
Language: Python
Severity: Error
Category: Security
CWE: 502
Description
Unsafe YAML deserialization. Make sure to use safe deserialization methods to avoid execution or arbitrary code.
Learn More
Non-Compliant Code Examples
from ruamel.yaml import YAML
foo = YAML(typ='unsafe')
def myfunction(arg):
bar = YAML(typ='base')
Compliant Code Examples
foo = YAML(typ='unsafe')
def myfunction(arg):
bar = YAML(typ='base')
from ruamel.yaml import YAML
default = YAML()
rt = YAML(typ='rt')
safe = YAML(typ='safe')
Seamless integrations. Try Datadog Code Analysis