diff --git a/test.py b/test.py new file mode 100644 index 0000000..19f915b --- /dev/null +++ b/test.py @@ -0,0 +1,6 @@ +import yaml + + +yaml.load(Loader=yaml.Loader) + +yaml.unsafe_load("something") diff --git a/torchfl-org-yaml-rule-test.yaml b/torchfl-org-yaml-rule-test.yaml new file mode 100644 index 0000000..fd6fb59 --- /dev/null +++ b/torchfl-org-yaml-rule-test.yaml @@ -0,0 +1,53 @@ +rules: + - id: avoid-pyyaml-load + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + cwe: + - "CWE-502: Deserialization of Untrusted Data" + references: + - https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation + - https://nvd.nist.gov/vuln/detail/CVE-2017-18342 + category: security + technology: + - pyyaml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Commons Clause License Condition v1.0[LGPL-2.1-only] + rule-origin-note: published from torchfl-org-yaml-rule-test.yaml in + git@github.com:torchfl-org/torchfl.git + languages: + - python + message: fukkkdsafsadfadsadddblahDetected a possible YAML deserialization vulnerability. + `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` + are all known to be unsafe methods of deserializing YAML. An attacker with + control over the YAML input could create special YAML input that allows + the attacker to run arbitrary Python code. This would allow the attacker + to steal files, download and install malware, or otherwise take over the + machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead. blah blah.blah + fix-regex: + regex: unsafe_load + replacement: safe_load + count: 1 + severity: ERROR + patterns: + - pattern-inside: | + import yaml + ... + - pattern-not-inside: | + $YAML = ruamel.yaml.YAML(...) + ... + - pattern-either: + - pattern: yaml.load(..., Loader=yaml.Loader, ...) + - pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load(..., Loader=yaml.CLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.Loader, ...) + - pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.CLoader, ...) + - pattern: yaml.unsafe_load(...)