Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25857

Опубликовано: 30 авг. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

A flaw was found in the org.yaml.snakeyaml package. This flaw allows an attacker to cause a denial of service (DoS) due to missing nested depth limitation for collections.

Отчет

For RHEL-8 it's downgraded to moderate because "snakeyaml" itself in RHEL 8 or RHEL-9 isn't shipped and "prometheus-jmx-exporter" is needed as build dependency. And it's not directly exploitable, hence severity marked as moderate. Red Hat Integration and AMQ products are not vulnerable to this flaw, so their severity has been lowered to moderate. Red Hat Single Sign-On uses snakeyaml from liquibase-core and is only used when performing migrations and would require administrator privileges to execute, hence severity marked as Low. Red Hat Fuse 7 is now in Maintenance Support Phase and details about its fix should be present soon. However, Red Hat Fuse Online (Syndesis) does will not contain the fix for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2snakeyamlAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat A-MQ OnlinesnakeyamlNot affected
Red Hat build of Debezium 1snakeyamlNot affected
Red Hat build of QuarkussnakeyamlAffected
Red Hat Enterprise Linux 7snakeyamlOut of support scope
Red Hat Integration Camel K 1snakeyamlAffected
Red Hat Integration Camel Quarkus 1snakeyamlAffected
Red Hat Integration Service RegistrysnakeyamlOut of support scope
Red Hat JBoss Data Grid 7snakeyamlOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2126789snakeyaml: Denial of Service due to missing nested depth limitation for collections

EPSS

Процентиль: 53%
0.00299
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

CVSS3: 7.5
nvd
почти 3 года назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

CVSS3: 7.5
debian
почти 3 года назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable t ...

rocky
почти 3 года назад

Moderate: prometheus-jmx-exporter security update

CVSS3: 7.5
github
почти 3 года назад

Uncontrolled Resource Consumption in snakeyaml

EPSS

Процентиль: 53%
0.00299
Низкий

7.5 High

CVSS3

Уязвимость CVE-2022-25857