Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-1471

Опубликовано: 01 дек. 2022
Источник: debian
EPSS Критический

Описание

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
snakeyamlunfixedpackage

Примечания

  • https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2

EPSS

Процентиль: 100%
0.93849
Критический

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 3 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 9.8
redhat
около 3 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 8.3
nvd
около 3 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

rocky
почти 3 года назад

Important: prometheus-jmx-exporter security update

CVSS3: 8.3
github
почти 3 года назад

SnakeYaml Constructor Deserialization Remote Code Execution

EPSS

Процентиль: 100%
0.93849
Критический