SnakeYAML Insecure Deserialization (CVE-2022-1471)

Related Vulnerabilities: CVE-2022-1471  

Check Point Reference: CPAI-2022-1931 Date Published: 24 Dec 2023 Severity: Critical Last Updated: Sunday 24 December, 2023 Source: Industry Reference:CVE-2022-1471
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? SnakeYAML Project prior to 2.0 Vulnerability Description An insecure deserialization vulnerability exists in SnakeYAML. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.