
PEACH
Un cadre d’isolation des locataires
CVE-2017-20285 is a deserialization/unsafe reflection vulnerability in the YAML module for Perl (versions before 1.30) that allows a crafted YAML document to trigger the DESTROY method of arbitrary classes loaded in the process. When a perl/hash:Class tag is parsed, the YAML loader blesses a hash into the named class; Perl then automatically invokes that class's DESTROY destructor when the object goes out of scope. A concrete example is File::Temp::Dir from core Perl, whose DESTROY method can delete an attacker-specified directory tree. The vulnerability was originally reported in May 2017 and formally assigned CVE-2017-20285, with a CVSS v3.1 base score of 7.4 (High) (Red Hat Advisory, Github Advisory).
The root cause is classified as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code / Unsafe Reflection) and CWE-502 (Deserialization of Untrusted Data). When the YAML loader encounters a tag such as !perl/hash:Foo::Bar, it calls Perl's CORE::bless to instantiate an object of the attacker-specified class using attacker-supplied field data, without any allowlist or validation of the class name. Because Perl automatically calls DESTROY on blessed objects when they go out of scope, an attacker can trigger any destructor present in the process's loaded class namespace — not just File::Temp::Dir. The issue was publicly disclosed via a GitHub issue in May 2017 with a working proof-of-concept demonstrating File::Temp::Dir-based directory deletion (yaml-pm Issue #176, Red Hat Bugzilla).
Successful exploitation allows an unauthenticated network attacker to trigger arbitrary class destructors within the Perl process parsing the malicious YAML document. The most documented impact is deletion of attacker-specified directory trees via File::Temp::Dir, representing a high availability and integrity risk. Depending on which classes are loaded in the target process, other destructors could cause additional unintended side effects, including potential code execution paths, making the actual impact highly context-dependent (Red Hat Advisory, yaml-pm Issue #176).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability requires high attack complexity (CVSS AC:High), as exploitation depends on which classes are loaded in the target process at the time the malicious YAML is parsed. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been identified. The EPSS score is reported as 0.0, reflecting very low observed exploitation probability (Red Hat Advisory, Github Advisory).
YAML module (versions < 1.30) and has dangerous classes such as File::Temp::Dir loaded in its process.perl/hash:Class tag to bless a hash into a target class with attacker-controlled field values, for example:---
obj: !perl/hash:File::Temp::Dir
_dirname: /path/to/target/directoryFile::Temp::Dir and the resulting object goes out of scope, Perl automatically calls DESTROY, which deletes the directory tree specified in the object's fields.perl/hash:, perl/array:, or similar Perl-specific YAML tags in request bodies or uploaded files.Upgrade the Perl YAML module to version 1.30 or later, which changes the default value of $YAML::LoadBlessed to undef (false), preventing automatic blessing of YAML nodes into arbitrary classes (yaml-pm commit 7736f38). For applications that cannot immediately upgrade, set $YAML::LoadBlessed = 0 explicitly before parsing any untrusted YAML input — this was introduced as a configurable option in version 1.25 (yaml-pm commit 471314b). Additionally, avoid parsing YAML from untrusted network sources, implement input validation to reject documents containing Perl-specific tags, and audit loaded Perl classes for dangerous DESTROY implementations.
The vulnerability was originally reported to the yaml-pm project maintainers via a GitHub issue in May 2017 by researcher dod38fr, who provided a working example and linked to a Debian bug report demonstrating the File::Temp::Dir attack vector (yaml-pm Issue #176). The fix was implemented by Tina Müller (TINITA) across two commits — first introducing the $YAML::LoadBlessed option in 2018, then changing its default to false (disabled) in version 1.30 in 2020. Red Hat tracked the issue via Bugzilla and assigned it a high severity rating (Red Hat Bugzilla).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."