Code execution in SLO Generator via YAML Payload
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 1.6%
from disclosure to weapon3 days
Published on NVDOct 4
1st PoC+3d
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short
SLO Generator can execute arbitrary code when processing specially crafted YAML files. An attacker who can provide a malicious YAML file to the application could run code with the privileges of the SLO Generator process.
Technical detail
The vulnerability exists in YAML file parsing without proper deserialization controls (CWE-94). An attacker can craft a YAML payload that triggers code execution during file loading. Exploitation requires the ability to supply or control YAML input to the SLO Generator application.
Summary generated and translated by AI from the official description.
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past https://github.com/google/slo-generator/pull/173
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
Google LLC · SLO Generatorpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50385cve_referencepacketstormsecurity.com/files/164426/Google-SLO-Generator-2.0.0-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.