Back

MEDIUM

DoS in SnakeYAML

Published Sep 5, 2022

Description

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.

Affected products

Remediation

Red Hat statement

Red Hat Build of Quarkus is not affected by this issue as it already includes the fixed version.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Sep 5, 2022
Updated Aug 3, 2024
Reserved Aug 25, 2022
CISA Vulnrichment
Updated Jul 22, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 5, 2022
ENISA EUVD
Assigner Google
Published Sep 5, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-6769 GHSA-9W3M-GQGF-C4P9