Описание
kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases. There are no known workarounds.
Ссылки
- Patch
- Release Notes
- Vendor Advisory
- Patch
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.53.0 (исключая)
cpe:2.3:a:kaml_project:kaml:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00237
Низкий
7.5 High
CVSS3
Дефекты
CWE-776
Связанные уязвимости
CVSS3: 7.5
github
почти 3 года назад
kaml has potential denial of service while parsing input with anchors and aliases
EPSS
Процентиль: 47%
0.00237
Низкий
7.5 High
CVSS3
Дефекты
CWE-776