Snakeyaml Project
snakeyaml_project
8 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml...Show more |
2Fedoraproject Snakeyaml Project2Fedora SnakeyamlNov 21, 2024 Nov 11, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by...Show more |
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlNov 21, 2024 Sep 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlNov 21, 2024 Sep 5, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlNov 21, 2024 Sep 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlNov 21, 2024 Aug 30, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections. |
4Fedoraproject OracleQuarkus+1 more4Fedora Peoplesoft Enterprise Pt PeopletoolsQuarkus+1 moreNov 21, 2024 Dec 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564. |