Skip to content

Conversation

@lgutter
Copy link

@lgutter lgutter commented Feb 11, 2020

with yaml.load, a code execution was possible when called without an explicit Loader.
To solve this with backwards compatibility, if the new FullLoader is found, it is used.
If it is not found, the old SafeLoader is used, Which has slightly less functionality but is safe.

with yaml.load, a code execution was possible when called without
an explicit Loader.
To solve this with backwards compatibility,
if the new FullLoader is found, it is used.
If it is not found, the old SafeLoader is used,
Which has slightly less functionality but is safe.
@yitam
Copy link

yitam commented Oct 18, 2021

Is someone going to review this or make any change? Can't upload reports anymore

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants