Description


Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.

Related CPE's



o

fedoraproject

fedora

2

Weaknesses



CWE-121


CWE-787

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H

5.8 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-11T12:15:11.003Z

3 years ago

Last modified

2024-11-21T06:23:56.797Z

1 year ago