Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj49-j7rc-h54f

Опубликовано: 25 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Esoteric YamlBeans XML Entity Expansion vulnerability

An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and memory consumption, such as a Java Out-of-Memory exception.

Пакеты

Наименование

com.esotericsoftware.yamlbeans:yamlbeans

maven
Затронутые версииВерсия исправления

<= 1.15

Отсутствует

EPSS

Процентиль: 5%
0.00021
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-400
CWE-611

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and memory consumption, such as a Java Out-of-Memory exception.

EPSS

Процентиль: 5%
0.00021
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-400
CWE-611