The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Redhat
Subscribe
|
Amq Broker
Subscribe
Amq Clients
Subscribe
Camel Spring Boot
Subscribe
Enterprise Linux
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Fuse
Subscribe
Ocp Tools
Subscribe
Openshift
Subscribe
Openshift Application Runtimes
Subscribe
Red Hat Single Sign On
Subscribe
Rhosemc
Subscribe
Satellite
Subscribe
Service Registry
Subscribe
|
|
Snakeyaml Project
Subscribe
|
Snakeyaml
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3132-1 | snakeyaml security update |
EUVD |
EUVD-2022-6470 | The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections. |
Github GHSA |
GHSA-3mc7-4q67-w48m | Uncontrolled Resource Consumption in snakeyaml |
Ubuntu USN |
USN-5944-1 | SnakeYAML vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 28 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T21:57:41.551Z
Reserved: 2022-02-24T00:00:00
Link: CVE-2022-25857
No data.
Status : Modified
Published: 2022-08-30T05:15:07.667
Modified: 2024-11-21T06:53:07.563
Link: CVE-2022-25857
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN