Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-1471

Опубликовано: 01 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS3: 8.3

Описание

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

ignored

backport infeasible
esm-apps/bionic

ignored

backport infeasible
esm-apps/focal

ignored

backport infeasible
esm-apps/jammy

ignored

backport infeasible
esm-apps/noble

ignored

backport infeasible
esm-apps/xenial

ignored

backport infeasible
esm-infra-legacy/trusty

ignored

backport infeasible
focal

ignored

end of standard support, was ignored [backport infeasible]
jammy

ignored

backport infeasible

Показывать по

EPSS

Процентиль: 100%
0.93796
Критический

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 8.3
nvd
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 8.3
debian
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be i ...

rocky
больше 2 лет назад

Important: prometheus-jmx-exporter security update

CVSS3: 8.3
github
больше 2 лет назад

SnakeYaml Constructor Deserialization Remote Code Execution

EPSS

Процентиль: 100%
0.93796
Критический

8.3 High

CVSS3