Vulnerability Details CVE-2021-23338
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.089
EPSS Ranking 92.1%
CVSS Severity
CVSS v3 Score 6.6
CVSS v2 Score 6.5
Products affected by CVE-2021-23338
-
cpe:2.3:a:microsoft:qlib:0.5.0
-
cpe:2.3:a:microsoft:qlib:0.5.1
-
cpe:2.3:a:microsoft:qlib:0.6.0
-
cpe:2.3:a:microsoft:qlib:0.6.1
-
cpe:2.3:a:microsoft:qlib:0.6.2