Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-25857

Опубликовано: 30 авг. 2022
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 7.5

Описание

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

РелизСтатусПримечание
bionic

released

1.23-1+deb10u1build0.18.04.1
devel

not-affected

1.33-1
esm-apps/bionic

released

1.23-1+deb10u1build0.18.04.1
esm-apps/focal

released

1.25+ds-2ubuntu0.1
esm-apps/jammy

released

1.29-1ubuntu0.22.04.1
esm-apps/xenial

released

1.12-2ubuntu0.16.04.1~esm1
esm-infra-legacy/trusty

not-affected

1.12-2ubuntu0.14.04.1~esm1
focal

released

1.25+ds-2ubuntu0.1
jammy

released

1.29-1ubuntu0.22.04.1
kinetic

released

1.29-1ubuntu0.22.10.1

Показывать по

EPSS

Процентиль: 53%
0.00299
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 3 года назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

CVSS3: 7.5
nvd
почти 3 года назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

CVSS3: 7.5
debian
почти 3 года назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable t ...

rocky
почти 3 года назад

Moderate: prometheus-jmx-exporter security update

CVSS3: 7.5
github
почти 3 года назад

Uncontrolled Resource Consumption in snakeyaml

EPSS

Процентиль: 53%
0.00299
Низкий

7.5 High

CVSS3