CVE-2017-20285: 
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2017-20285 is a deserialization/unsafe reflection vulnerability in the YAML module for Perl (versions before 1.30) that allows a crafted YAML document to trigger the DESTROY method of arbitrary classes loaded in the process. When a perl/hash:Class tag is parsed, the YAML loader blesses a hash into the named class; Perl then automatically invokes that class's DESTROY destructor when the object goes out of scope. A concrete example is File::Temp::Dir from core Perl, whose DESTROY method can delete an attacker-specified directory tree. The vulnerability was originally reported in May 2017 and formally assigned CVE-2017-20285, with a CVSS v3.1 base score of 7.4 (High) (Red Hat Advisory, Github Advisory).

Détails techniques

The root cause is classified as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code / Unsafe Reflection) and CWE-502 (Deserialization of Untrusted Data). When the YAML loader encounters a tag such as !perl/hash:Foo::Bar, it calls Perl's CORE::bless to instantiate an object of the attacker-specified class using attacker-supplied field data, without any allowlist or validation of the class name. Because Perl automatically calls DESTROY on blessed objects when they go out of scope, an attacker can trigger any destructor present in the process's loaded class namespace — not just File::Temp::Dir. The issue was publicly disclosed via a GitHub issue in May 2017 with a working proof-of-concept demonstrating File::Temp::Dir-based directory deletion (yaml-pm Issue #176, Red Hat Bugzilla).

Impact

Successful exploitation allows an unauthenticated network attacker to trigger arbitrary class destructors within the Perl process parsing the malicious YAML document. The most documented impact is deletion of attacker-specified directory trees via File::Temp::Dir, representing a high availability and integrity risk. Depending on which classes are loaded in the target process, other destructors could cause additional unintended side effects, including potential code execution paths, making the actual impact highly context-dependent (Red Hat Advisory, yaml-pm Issue #176).

Exploitabilité

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability requires high attack complexity (CVSS AC:High), as exploitation depends on which classes are loaded in the target process at the time the malicious YAML is parsed. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been identified. The EPSS score is reported as 0.0, reflecting very low observed exploitation probability (Red Hat Advisory, Github Advisory).

Étapes d’exploitation

  1. Identify target: Locate a Perl application that parses untrusted YAML input using the YAML module (versions < 1.30) and has dangerous classes such as File::Temp::Dir loaded in its process.
  2. Craft malicious YAML: Construct a YAML document using a perl/hash:Class tag to bless a hash into a target class with attacker-controlled field values, for example:
---
obj: !perl/hash:File::Temp::Dir
  _dirname: /path/to/target/directory
  1. Deliver the payload: Submit the crafted YAML document to the application via any input vector that triggers YAML parsing (e.g., file upload, API request body, configuration input).
  2. Trigger DESTROY: When the YAML loader blesses the hash into File::Temp::Dir and the resulting object goes out of scope, Perl automatically calls DESTROY, which deletes the directory tree specified in the object's fields.
  3. Achieve objective: Depending on loaded classes, the attacker achieves file/directory deletion, or potentially other unintended side effects from other available destructors (yaml-pm Issue #176, Red Hat Bugzilla).

Indicateurs de compromis

  • Logs: Application logs showing unexpected YAML parsing errors or warnings related to blessed object creation; Perl warnings about unknown classes being instantiated during YAML load.
  • File System: Unexpected deletion of directories or files that correspond to paths accessible by the Perl application's service account; missing directories that were previously present.
  • Process: Perl processes spawning with unusual YAML input from network sources; unexpected invocation of destructor-related code paths in application traces.
  • Network: Inbound requests containing YAML payloads with perl/hash:, perl/array:, or similar Perl-specific YAML tags in request bodies or uploaded files.

Atténuation et solutions de contournement

Upgrade the Perl YAML module to version 1.30 or later, which changes the default value of $YAML::LoadBlessed to undef (false), preventing automatic blessing of YAML nodes into arbitrary classes (yaml-pm commit 7736f38). For applications that cannot immediately upgrade, set $YAML::LoadBlessed = 0 explicitly before parsing any untrusted YAML input — this was introduced as a configurable option in version 1.25 (yaml-pm commit 471314b). Additionally, avoid parsing YAML from untrusted network sources, implement input validation to reject documents containing Perl-specific tags, and audit loaded Perl classes for dangerous DESTROY implementations.

Réactions de la communauté

The vulnerability was originally reported to the yaml-pm project maintainers via a GitHub issue in May 2017 by researcher dod38fr, who provided a working example and linked to a Debian bug report demonstrating the File::Temp::Dir attack vector (yaml-pm Issue #176). The fix was implemented by Tina Müller (TINITA) across two commits — first introducing the $YAML::LoadBlessed option in 2018, then changing its default to false (disabled) in version 1.30 in 2020. Red Hat tracked the issue via Bugzilla and assigned it a high severity rating (Red Hat Bugzilla).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2019-25777HIGH8.1
  • Linux Debian logoLinux Debian
  • perl-YAML
NonOuiOct 05, 2026
CVE-2017-20285HIGH7.4
  • Linux Debian logoLinux Debian
  • libyaml-perl
NonOuiOct 05, 2026
CVE-2026-94291MEDIUM6.5
  • Linux Debian logoLinux Debian
  • epiphany-browser
NonNonOct 05, 2026
CVE-2026-97873MEDIUM5.3
  • Bouncy Castle logoBouncy Castle
  • bouncycastle
NonOuiOct 03, 2026
CVE-2026-19954NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-whois-raw-perl
NonNonOct 05, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités