UBUNTU-CVE-2022-25857
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-25857
UBUNTU-CVE-2022-25857
Summary:
Details: The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
References: https://ubuntu.com/security/CVE-2022-25857, https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174, https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174, https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360, https://bitbucket.org/snakeyaml/snakeyaml/issues/525, https://ubuntu.com/security/notices/USN-5944-1, https://www.cve.org/CVERecord?id=CVE-2022-25857
Affected packages
Package
Name: snakeyaml
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
