Description
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1404 | The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564. |
Github GHSA |
GHSA-rvwf-54qp-4r6v | SnakeYAML Entity Expansion during load operation |
Ubuntu USN |
USN-7368-1 | SnakeYAML vulnerability |
References
History
No history.
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Oracle
Subscribe
Peoplesoft Enterprise Pt Peopletools
Subscribe
Quarkus
Subscribe
Quarkus
Subscribe
Redhat
Subscribe
Amq Streams
Subscribe
Enterprise Linux
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Snakeyaml Project
Subscribe
Snakeyaml
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:28:55.802Z
Reserved: 2019-12-12T00:00:00.000Z
Link: CVE-2017-18640
No data.
Status : Modified
Published: 2019-12-12T03:15:10.850
Modified: 2024-11-21T03:20:32.813
Link: CVE-2017-18640
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN