b03c4759aa
Before this patch yaml.Loader was used by the engine to create custom yaql-enabled yaml loader. It is unsafe do to so, because yaml.Loader is capable of creating custom python objects from specifically constructed yaml files. After this patch all yaml load operations are performed with safe loaders instead. Also use SafeConstructor instead of Constructor. Change-Id: I61a3c42d73608b5d013285f015a45f4774d264e3 Closes-Bug: #1586079
10 lines
405 B
YAML
10 lines
405 B
YAML
---
|
|
security:
|
|
- cve-2016-4972 has been addressed. In ceveral places
|
|
Murano used loaders inherited directly from yaml.Loader
|
|
when parsing MuranoPL and UI files from packages.
|
|
This is unsafe, because this loader is capable of creating
|
|
custom python objects from specifically constructed
|
|
yaml files. With this change all yaml loading operations are done
|
|
using safe loaders instead.
|