Input validation error in PyYAML - CVE-2020-14343

 

Input validation error in PyYAML - CVE-2020-14343

Published: July 4, 2021 / Updated: November 28, 2025


Vulnerability identifier: #VU54520
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14343
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when processing untrusted YAML files through the full_load method or with the FullLoader loader. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system by abusing the python/object/new constructor.

Note, the vulnerability exists due to incomplete patch for vulnerability #VU25823.


Affected software

PyYAML
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
Junos cRPD
Gentoo Linux
SUSE OpenStack Cloud
Red Hat CodeReady Linux Builder for x86_64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
SUSE Manager Tools
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
openEuler
Ubuntu
Fedora
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
python38-PyMySQL
python38-Cython
python38-wheel-wheel
python38-wheel
python38-markupsafe
python38-asn1crypto
python38-scipy
python38-pysocks
python38-six
python38-cffi
python38-numpy-f2py
python38-numpy-doc
python38-numpy
python38-urllib3
python38-babel
python38-cryptography
python38-psycopg2-tests
python38-psycopg2-doc
python38-psycopg2
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python38-test
python38-libs
python38-devel
python38-tkinter
python38-rpm-macros
python38-idle
python38
python38-debug
python38-ply
python38-lxml
python38-mod_wsgi
python-PyYAML
python-PyYAML-debuginfo
python-PyYAML-debugsource
python3-PyYAML
python2-PyYAML
python2-PyYAML-debuginfo
python3-PyYAML-debuginfo
python-yaml (Ubuntu package)
python3-yaml (Ubuntu package)
pyyaml
python3-pyyaml
pyyaml-debuginfo
pyyaml-debugsource
dev-python/pyyaml
python38-pyyaml
PyYAML
python38-psutil
python38-pip-wheel
python38-pip
python38-setuptools
python38-setuptools-wheel
python38-pytz
PeopleSoft Enterprise PeopleTools
IBM Cloud Pak for Data System
Juniper Cloud Native Router
Dell EMC PowerStore Family Operating System
Cloud Pak for Network Automation

How to mitigate CVE-2020-14343

Install updates from vendor's website.

PyYAML - update to 5.4
python38-PyMySQL - update to 0.10.1-1
python38-Cython - update to 0.29.14-4
python38-wheel-wheel - update to 0.33.6-5
python38-wheel - update to 0.33.6-5
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy-f2py - update to 1.17.3-5
python38-numpy-doc - update to 1.17.3-5
python38-numpy - update to 1.17.3-5
python38-urllib3 - update to 1.25.7-4
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
Dell EMC PowerStore Family Operating System - update to 2.1.1.2- 1885194
Cloud Pak for Network Automation - update to 2.6.4
python38-babel - update to 2.7.0-10
python38-cryptography - update to 2.8-3
python38-psycopg2-tests - update to 2.8.4-4
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2 - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-4
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
PowerStoreX OS - update to 3.2.1.5-2424458
python38-test - update to 3.8.6-3
python38-libs - update to 3.8.6-3
python38-devel - update to 3.8.6-3
python38-tkinter - update to 3.8.6-3
python38-rpm-macros - update to 3.8.6-3
python38-idle - update to 3.8.6-3
python38 - update to 3.8.6-3
python38-debug - update to 3.8.6-3
python38-ply - update to 3.11-10
python38-lxml - update to 4.4.1-5
python38-mod_wsgi - update to 4.6.8-3
python-PyYAML - addressed in versions 5.1.2-26.15.1, 5.3.1-28.6.1
python-PyYAML-debuginfo - addressed in versions 5.1.2-26.15.1, 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python-PyYAML-debugsource - addressed in versions 5.1.2-26.15.1, 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python3-PyYAML - addressed in versions 5.1.2-26.15.1, 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python2-PyYAML - update to 5.1.2-150000.3.6.1
python2-PyYAML-debuginfo - update to 5.1.2-150000.3.6.1
python3-PyYAML-debuginfo - addressed in versions 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python-yaml (Ubuntu package) - update to 5.3.1-1ubuntu0.1
python3-yaml (Ubuntu package) - addressed in versions 5.3.1-1ubuntu0.1, 5.3.1-2ubuntu0.1
pyyaml - update to 5.3.1-4
python3-pyyaml - update to 5.3.1-4
pyyaml-debuginfo - update to 5.3.1-4
pyyaml-debugsource - update to 5.3.1-4
dev-python/pyyaml - update to 5.4
python38-pyyaml - update to 5.4.1-1
PyYAML - addressed in versions 5.4.1-1.fc32, 5.4.1-1.fc33
python38-psutil - update to 5.6.4-3
python38-pip-wheel - update to 19.3.1-1
python38-pip - update to 19.3.1-1
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
python38-setuptools - update to 41.6.0-4
python38-setuptools-wheel - update to 41.6.0-4
python38-pytz - update to 2019.3-3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins