
PEACH
Un cadre d’isolation des locataires
CVE-2019-25777 is an arbitrary code execution vulnerability in the YAML module for Perl (also known as yaml-pm) affecting all versions before 1.27_001. The flaw allows a maliciously crafted perl/glob YAML document to replace arbitrary Perl package variables, which can be leveraged to enable code loading and subsequently execute arbitrary Perl code. The vulnerability was originally reported on April 27, 2019, and formally assigned a CVE and published to the NVD and GitHub Advisory Database in October 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Red Hat Advisory, Github Advisory).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data) and CWE-914 (Improper Control of Dynamically-Identified Variables). When the YAML module processes a perl/glob document, it assigns a value to a named package variable without any restriction on which variable can be targeted. An attacker can exploit this in two stages across separate Load() calls within the same process: first, supply a perl/glob document that sets $YAML::LoadCode or $YAML::UseCode to a truthy value (enabling code loading, which is off by default); then supply a perl/code document that is passed to Perl's string eval, executing arbitrary code. The fix, committed by Tina Müller on April 27, 2019, gates glob loading behind a check that $YAML::LoadBlessed and load_code are both enabled (GitHub Issue, Patch).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary Perl code with the privileges of the application process that invokes YAML::Load(). This results in full compromise of confidentiality, integrity, and availability of the affected system. Depending on the application context, an attacker could exfiltrate sensitive data, modify application state, install backdoors, or pivot to other systems accessible from the compromised process (Red Hat Advisory, Github Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The attack requires the ability to supply two separate YAML documents to distinct Load() calls within the same process, which raises the attack complexity to High (reflected in the CVSS score). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the EPSS score is reported as 0.0 (Red Hat Advisory, Github Advisory).
Load() calls within the same process.perl/glob YAML document that targets the $YAML::LoadCode or $YAML::UseCode package variable and sets it to a truthy value, e.g.:--- !!perl/glob
package: YAML
name: LoadCode
SCALAR: 1YAML::Load() call, enabling code loading for all subsequent Load() calls in the process.perl/code YAML document containing the arbitrary Perl code to execute, e.g.:--- !!perl/code
'system("id > /tmp/pwned");'YAML::Load() call in the same process; the code is passed to string eval and executed with the privileges of the application process (GitHub Issue, Patch).!!perl/glob or !!perl/code tags from untrusted input sources.sh, bash, curl, wget) following YAML document processing.Upgrade the Perl YAML module to version 1.27_001 or later (the fix was included in the YAML-1.28 release on CPAN). If immediate patching is not possible, restrict the application so that untrusted input cannot be passed to YAML::Load(), or implement input validation to reject documents containing !!perl/glob and !!perl/code tags before processing. Ensure that $YAML::LoadCode and $YAML::UseCode remain set to their default values (false/0) and are not modifiable by external input (Github Advisory, Patch).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."