Code Execution Vulnerability in SLO Generator via Crafted YAML Files

Code Execution Vulnerability in SLO Generator via Crafted YAML Files

CVE-2021-22557 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past https://github.com/google/slo-generator/pull/173

Learn more about our Web Application Penetration Testing UK.