CVE-2017-20285criticalCWE-470CWE-502

CVE-2017-20285: critical vulnerability in YAML

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes

Published · Updated

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
YAML