Skip to content

CVE-2022-25857 @ Maven-org.yaml:snakeyaml-1.26 #6

@jerp1979

Description

@jerp1979

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-25857
Checkmarx Project: jerp1979/java-faker
Repository URL: https://github.com/jerp1979/java-faker
Branch: master
Scan ID: 8f3fa71f-fe46-4bc8-9378-781a0403538e


The package org.yaml:snakeyaml before 1.31 is vulnerable to Denial of Service (DoS) due to missing nested depth limitation for collections. This CVE is duplicated by CVE-2022-38749. Checkmarx analyzed this thoroughly to understand if there was a difference between the CVEs but they reference the same issue and the fix is exactly the same.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 1.33.0.redhat-00002

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions