Use of unsafe yaml load in dynparam
Vulnerability Description
A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through this flaw, a local or remote user can craft and execute arbitrary Python code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39780
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Florencia Cabral Berenfus, Ubuntu Robotics Team
More from Open Source Robotics Foundation
View All →Affected Vendor
Open Source Robotics Foundation
View all reports →