Skip to content

Conversation

vsysoev
Copy link
Contributor

@vsysoev vsysoev commented May 20, 2025

No description provided.

Sysoev, Vladimir added 2 commits May 20, 2025 21:41
Signed-off-by: Sysoev, Vladimir <[email protected]>
A vulnerability was discovered in the PyYAML library in versions before 5.4,
where it is susceptible to arbitrary code execution when it processes untrusted
YAML files through the full_load method or with the FullLoader loader.
Applications that use the library to process untrusted input may be vulnerable
to this flaw. This flaw allows an attacker to execute arbitrary code on the system
by abusing the python/object/new constructor.
This flaw is due to an incomplete fix for CVE-2020-1747.

Signed-off-by: Sysoev, Vladimir <[email protected]>
@vsysoev vsysoev changed the title WIP: Update pytesseract to version 0.3.13 WIP: Update dependency to the last version May 20, 2025
Sysoev, Vladimir added 6 commits May 20, 2025 21:49
Signed-off-by: Sysoev, Vladimir <[email protected]>
SetuptoolsDeprecationWarning: License classifiers are deprecated.

Signed-off-by: Sysoev, Vladimir <[email protected]>
Signed-off-by: Sysoev, Vladimir <[email protected]>
Signed-off-by: Sysoev, Vladimir <[email protected]>
Signed-off-by: Sysoev, Vladimir <[email protected]>
Signed-off-by: Sysoev, Vladimir <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant