Python Yaml Privilege Escalation
Python Yaml package is vulnerable to execute arbitrary command.
Now execute the bash
in privilege mode.
Start a listener in local machine.
Then execute Python script that contains the following YAML
code as root.
Sometimes we might be able to remote code execution by using Base64 encoded payload.
References
Last updated