Commit 0cedb2a
committed
Deprecate/warn usage of yaml.load(input)
The `load` and `load_all` methods will issue a warning when they are
called without the 'Loader=' parameter. The warning will point to a URL
that is always up to date with the latest information on the usage of
`load`.
There are several ways to stop the warning:
* Use `full_load(input)` - sugar for `yaml.load(input, FullLoader)`
* FullLoader is the new safe but complete loader class
* Use `safe_load(input)` - sugar for `yaml.load(input, SafeLoader)`
* Make sure your input YAML consists of the 'safe' subset
* Use `unsafe_load(input)` - sugar for `yaml.load(input, UnsafeLoader)`
* Make sure your input YAML consists of the 'safe' subset
* Use `yaml.load(input, Loader=yaml.<loader>)`
* Or shorter `yaml.load(input, yaml.<loader>)`
* Where '<loader>' can be:
* FullLoader - safe, complete Python YAML loading
* SafeLoader - safe, partial Python YAML loading
* UnsafeLoader - more explicit name for the old, unsafe 'Loader' class
* yaml.warnings({'YAMLLoadWarning': False})
* Use this when you use third party modules that use `yaml.load(input)`
* Only do this if input is trusted
The above `load()` expressions all have `load_all()` counterparts.
You can get the original unsafe behavior with:
* `yaml.unsafe_load(input)`
* `yaml.load(input, Loader=yaml.UnsafeLoader)`
In a future release, `yaml.load(input)` will raise an exception.
The new loader called FullLoader is almost entirely complete as
Loader/UnsafeLoader but it does it avoids all known code execution
paths. It is the preferred YAML loader, and the current default for
`yaml.load(input)` when you get the warning.
Here are some of the exploits that can be triggered with UnsafeLoader
but not with FullLoader:
```
python -c 'import os, yaml; yaml.full_load("!!python/object/new:os.system [echo EXPLOIT!]")'`
python -c 'import yaml; print yaml.full_load("!!python/object/new:abs [-5]")'
python -c 'import yaml; yaml.full_load("!!python/object/new:eval [exit(5)]")' ; echo $?
python -c 'import yaml; yaml.full_load("!!python/object/new:exit [5]")' ; echo $?1 parent d13a3d0 commit 0cedb2a
File tree
8 files changed
+228
-64
lines changed- lib/yaml
- tests/lib
8 files changed
+228
-64
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
19 | 58 | | |
20 | 59 | | |
21 | 60 | | |
| |||
61 | 100 | | |
62 | 101 | | |
63 | 102 | | |
64 | | - | |
| 103 | + | |
65 | 104 | | |
66 | 105 | | |
67 | 106 | | |
68 | 107 | | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
69 | 112 | | |
70 | 113 | | |
71 | 114 | | |
72 | 115 | | |
73 | 116 | | |
74 | 117 | | |
75 | | - | |
| 118 | + | |
76 | 119 | | |
77 | 120 | | |
78 | 121 | | |
79 | 122 | | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
80 | 127 | | |
81 | 128 | | |
82 | 129 | | |
83 | 130 | | |
84 | 131 | | |
85 | 132 | | |
86 | 133 | | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
87 | 154 | | |
88 | 155 | | |
89 | 156 | | |
90 | 157 | | |
91 | | - | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
92 | 161 | | |
93 | 162 | | |
94 | 163 | | |
95 | 164 | | |
96 | 165 | | |
97 | 166 | | |
98 | 167 | | |
99 | | - | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
100 | 171 | | |
101 | 172 | | |
102 | 173 | | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
103 | 194 | | |
104 | 195 | | |
105 | 196 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
4 | 10 | | |
5 | 11 | | |
6 | 12 | | |
| |||
464 | 470 | | |
465 | 471 | | |
466 | 472 | | |
467 | | - | |
| 473 | + | |
468 | 474 | | |
469 | 475 | | |
470 | 476 | | |
| |||
481 | 487 | | |
482 | 488 | | |
483 | 489 | | |
484 | | - | |
| 490 | + | |
485 | 491 | | |
486 | 492 | | |
487 | 493 | | |
488 | | - | |
489 | | - | |
490 | | - | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
491 | 501 | | |
492 | | - | |
| 502 | + | |
493 | 503 | | |
494 | 504 | | |
495 | | - | |
| 505 | + | |
496 | 506 | | |
497 | 507 | | |
498 | 508 | | |
| |||
501 | 511 | | |
502 | 512 | | |
503 | 513 | | |
504 | | - | |
505 | | - | |
506 | | - | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
507 | 521 | | |
508 | | - | |
| 522 | + | |
509 | 523 | | |
510 | 524 | | |
511 | 525 | | |
| |||
532 | 546 | | |
533 | 547 | | |
534 | 548 | | |
535 | | - | |
| 549 | + | |
536 | 550 | | |
537 | 551 | | |
538 | 552 | | |
539 | 553 | | |
540 | 554 | | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
541 | 559 | | |
542 | 560 | | |
543 | 561 | | |
| |||
609 | 627 | | |
610 | 628 | | |
611 | 629 | | |
612 | | - | |
| 630 | + | |
613 | 631 | | |
614 | | - | |
| 632 | + | |
615 | 633 | | |
616 | | - | |
| 634 | + | |
617 | 635 | | |
618 | | - | |
| 636 | + | |
619 | 637 | | |
620 | | - | |
| 638 | + | |
621 | 639 | | |
622 | | - | |
| 640 | + | |
623 | 641 | | |
624 | | - | |
| 642 | + | |
625 | 643 | | |
626 | | - | |
| 644 | + | |
627 | 645 | | |
628 | | - | |
| 646 | + | |
629 | 647 | | |
630 | | - | |
| 648 | + | |
631 | 649 | | |
632 | | - | |
| 650 | + | |
633 | 651 | | |
634 | | - | |
| 652 | + | |
635 | 653 | | |
636 | | - | |
| 654 | + | |
637 | 655 | | |
638 | | - | |
| 656 | + | |
639 | 657 | | |
640 | | - | |
| 658 | + | |
641 | 659 | | |
642 | | - | |
| 660 | + | |
643 | 661 | | |
644 | | - | |
| 662 | + | |
645 | 663 | | |
646 | | - | |
| 664 | + | |
647 | 665 | | |
648 | | - | |
| 666 | + | |
649 | 667 | | |
650 | | - | |
| 668 | + | |
651 | 669 | | |
652 | | - | |
| 670 | + | |
653 | 671 | | |
654 | | - | |
| 672 | + | |
655 | 673 | | |
656 | | - | |
| 674 | + | |
657 | 675 | | |
658 | | - | |
| 676 | + | |
659 | 677 | | |
660 | | - | |
| 678 | + | |
661 | 679 | | |
662 | | - | |
| 680 | + | |
663 | 681 | | |
664 | | - | |
| 682 | + | |
665 | 683 | | |
666 | | - | |
| 684 | + | |
667 | 685 | | |
668 | | - | |
| 686 | + | |
669 | 687 | | |
670 | | - | |
| 688 | + | |
671 | 689 | | |
672 | | - | |
| 690 | + | |
673 | 691 | | |
674 | | - | |
| 692 | + | |
675 | 693 | | |
| 694 | + | |
| 695 | + | |
| 696 | + | |
| 697 | + | |
| 698 | + | |
| 699 | + | |
| 700 | + | |
| 701 | + | |
| 702 | + | |
| 703 | + | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
| 707 | + | |
| 708 | + | |
| 709 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
4 | 6 | | |
5 | 7 | | |
6 | 8 | | |
| |||
25 | 27 | | |
26 | 28 | | |
27 | 29 | | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
28 | 44 | | |
29 | 45 | | |
30 | 46 | | |
| |||
0 commit comments