YAML Vulnerability in Perl Affects Multiple Versions
CVE-2017-20285
Currently unrated
What is CVE-2017-20285?
A security vulnerability exists in YAML versions prior to 1.30 for Perl, which allows a loaded document to call the DESTROY method of arbitrary classes. This happens when a perl/hash:Class tag transforms a hash into the respective class, with the document defining the object's fields. When these objects go out of scope, Perl invokes the DESTROY method, which can lead to unintended actions based on the dynamically loaded classes. For instance, if the File::Temp::Dir module is present, it could potentially delete a directory tree specified within the document, exposing systems to significant risks if exploited.
