qlibGHSA-hjr4-fhgp-23g9
qlib Deserialization of Untrusted Data vulnerability
Medium6.6CVE-2021-23338 · Published May 24, 2022 · updated Oct 14, 2024
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pyqlib PyPI | < 0.7.0 | 0.7.0 |