CVE-2017-9731: Yocto Project Yp Core-Pyro

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Source entry in an ipk package.

Affected products

Published 2017-06-16. Last modified 2026-06-17.