CVE-2024-35060: High severity nasa ait core vulnerability
Published May 21, 2024
·Updated
An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.
Affected Software
3 affected components
nasa Ait Core<=2.5.2
nasa AIT-Core
Python YAML library
Event History
May 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35060?
CVE-2024-35060 is considered to have a high severity due to its potential for remote code execution.
2
How do I fix CVE-2024-35060?
To fix CVE-2024-35060, update the YAML Python library to the latest version to mitigate the vulnerability.
3
What types of attacks are possible with CVE-2024-35060?
CVE-2024-35060 allows attackers to execute arbitrary commands by supplying a crafted YAML file.
4
Which versions of NASA AIT-Core are affected by CVE-2024-35060?
NASA AIT-Core v2.5.2 is specifically affected by CVE-2024-35060.
5
Is the Python YAML library vulnerable to CVE-2024-35060?
Yes, the Python YAML library is vulnerable to CVE-2024-35060 when used in conjunction with affected software.