NA

CVE-2022-1471

Published: 01/12/2022 Updated: 19/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

snakeyaml project snakeyaml

Vendor Advisories

Synopsis Important: prometheus-jmx-exporter security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for prometheus-jmx-exporter is now available for Red Hat Enterprise Linux 8Red Hat Product Security ha ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat JBoss Enterprise Application Platform 74Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
概述 Important: Updated RHEL-7-based Middleware container images 类型/严重性 Security Advisory: Important 标题 Updated RHEL-7-based Middleware container images are now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives ...
Synopsis Important: Satellite 613 Release Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Satellite 613 The release contains anew version of Satellite and important security fixes ...
Synopsis Moderate: Red Hat build of Quarkus 2137 release and security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat build of QuarkusRed Hat Product Security has rated this update as having a security impact ofModerate A Common Vulnerability Scoring System (CVSS) base score, which gives adeta ...
Synopsis Critical: OpenShift Container Platform 4956 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4956 is now available with updates to packages and image ...
Synopsis Moderate: OpenShift Container Platform 4956 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4956 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Platf ...
Synopsis Important: Red Hat support for Spring Boot 2713 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Application RuntimesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 on RHEL 9 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 on RHEL 8 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 on RHEL 7 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
概述 Moderate: AMQ Clients 2023Q4 类型/严重性 Security Advisory: Moderate 标题 An update is now available for Red Hat AMQ ClientsRed Hat Product Security has rated this update as having an impact ofModerateA Common Vulnerability Scoring System (CVSS) base score, which gives a detailedseverity rating, is available for each vulnerabi ...
Synopsis Important: Red Hat build of Eclipse Vertx 434 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of Eclipse VertxRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives ...
Synopsis Moderate: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift GitOps 17Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ...
Synopsis Moderate: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift GitOps 16Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ...
Synopsis Important: Red Hat build of Quarkus 277 release and security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of Quarkus Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Moderate: OpenShift Container Platform 41052 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41052 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Important: OpenShift Container Platform 41052 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 41052 is now available with updates to packages and i ...
Synopsis Critical: jenkins and jenkins-2-plugins security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for O ...
Synopsis Important: Red Hat Single Sign-On 762 for OpenShift image security and enhancement update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 762, running on RedHat OpenShift Container Platform from the release of 311 up to the releaseof 4120Red Hat Product Security has rated t ...
Synopsis Important: Migration Toolkit for Runtimes security update Type/Severity Security Advisory: Important Topic An update is now available for Migration Toolkit for Runtimes (v101)Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) base score, whichgives a ...
Synopsis Important: jenkins and jenkins-2-plugins security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for ...
概述 Important: Red Hat Single Sign-On 762 security update on RHEL 8 类型/严重性 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems 标题 New Red Hat Single Sign-On 762 packages are now available for Red Hat Enterprise Linux 8Red H ...
Synopsis Important: Red Hat Single Sign-On 762 security update on RHEL 7 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 762 packages are now available for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Important: Red Hat Single Sign-On 762 security update on RHEL 9 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 762 packages are now available for Red Hat Enterprise Linux 9Red Hat ...
Synopsis Important: Red Hat Single Sign-On 762 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Hitachi Infrastructure Analytics Advisor contains the following vulnerabilities: CVE-2019-10172, CVE-2019-10202, CVE-2021-37533 Hitachi Ops Center Analyzer contains the following vulnerabilities: CVE-2019-10172, CVE-2019-10202, CVE-2021-37533, CVE-2022-1471, CVE-2023-1370, CVE-2023-26048, CVE-2023-26049 Hitachi Ops Center Analyzer viewpoi ...
Check Point Reference: CPAI-2022-1931 Date Published: 24 Dec 2023 Severity: Critical ...

Exploits

The PyTorch model server contains multiple vulnerabilities that can be chained together to permit an unauthenticated remote attacker arbitrary Java code execution The first vulnerability is that the management interface is bound to all IP addresses and not just the loop back interface as the documentation suggests The second vulnerability (CVE-20 ...

Github Repositories

Liquibase Spanner Extension A Liquibase extension adding support for Google Cloud Spanner Include this in your application project to run Liquibase database migration scripts against a Google Cloud Spanner database Performance Recommendations Executing multiple small DDL statements on Cloud Spanner can take a very long time This means that the standard recommendation to use

Drop in replacement for Snake YAML 1.33, this is a fork of the latest changes. The default constructors have been changed to no longer allow remote execution during deserialization.

SafeYAML Drop in replacement for Snake YAML 133, this is a fork of the latest changes The default constructors have been changed to no longer allow remote execution during deserialization For more information read - bitbucketorg/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in You probably don't need this dependency if you're not familiar with

Demo app Swagger URL: localhost:8080/swagger-ui/indexhtml TODO: Update Spring Boot Starter Parent 314 ASAP to fix vulnerabilities from dependencies: CVE-2023-33264 CVE-2023-26119 CVE-2022-45868 CVE-2022-1471 More info: mvnrepositorycom/artifact/orgspringframeworkboot/spring-boot-starter-parent/314

CVE-2022-1471 需要Java17、Python3、maven环境。使用Intellij IDEA打开,然后加载maven依赖,最后直接运行orgexampleApp中的main方法即可。 Windows11中可以运行。类Unix系统没有经过测试。 感谢 githubcom/artsploit/yaml-payload Java17, Python3 and maven is needed Open it with Intellij IDEA Then load the maven dependencies Fina

SnakeYAML-CVE-2022-1471-POC

snakeyaml_cve_poc SnakeYAML-CVE-2022-1471-POC build Either build the jar on your host with mvn clean compile assembly:single Or use docker to build an image with docker build -t snakeyaml run Run the container with docker run --rm -p8080:8080 snakeyaml or the jar if you built on your host with java -jar target/snakeyaml-10-SNAPSHOT-jar-with-dependenciesjar use Send a get re

Chrome extension to add "Why is this an issue?" tabs to SonarCloud for external issues.

sonarcloud-external-issue-helper-chrome-extension SonarCloud External Issue Helper is a Chrome extension to add missing "Why is this an issue?" tabs to SonarCloud for external issues in Generic issue data format SonarCloud supports a generic format for importing issues generated by external analysis tools, like linters External issues have an important limitation th

Create Java Properties files from a yaml file

yaml-props A Maven plugin to parse a yaml file with a certain structure to property files A bit of background This project was developed to replace the current way of generating property and settings files from Excel files at Truvo® After migrating from svn to git it became a real horror to maintain settings and messages (eg translations) in Excel files Certainly when

kb-app This is a spring and vue template for developers which is configured to be deployed and checks for vulnerabilities and more Table of Contents Structure Setup Project Run app with Docker Vue Frontend Spring boot Backend Liquibase changelog generation Deployment Todos Logs Security/Updates Security Updates Structure Spring Boot Java 17 LTS jUnit 5 Testcontain

Code for veracode blog

SnakeYAML-CVE-2022-1471-POC Code for veracode blog To demonstrate the Code Execution, Build the project using maven Execute python3 -m httpserver 8080 to run the http server Run exploitjava You should observe a HTTP GET request on the server To demonstrate how SnakeYAML 20 prevents the attack, comment out the 133 dependency in the pomxml Uncomment the 20 dependency, the

Deliberately Insecure Product

Deliberately-Insecure-Product Deliberately Insecure Product Known CVEs and Vulnerabilities tested Snakeyaml CVE-2022-1471 Top fixes Upgrade to snakeyaml 20 (Uncomment constraint in buildgradle) Use safe_constructor in v13x (Change the safe parameter to true) Project Features: Dependency sharing using gradle libsversionstoml

Spring Boot 3 and java 17 Application

bee004 Spring Boot 3 and java 17 Application Start Change the blank Git project to a a Spring Boot 3 RESTful application Use java 17 Set JDK version -> Java 17 Set Maven Vulnerabilities CVEs, that are reported vulnerabilities: CVE-2022-41854 (Out-of-bounds Write vulnerability) and CVE-2022-1471 (Deserialization of Untrusted Data vulnerability) Additional

Recent Articles

Trio of TorchServe flaws means PyTorch users need an urgent upgrade
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Meta, the project's maintainer, shrugs

A trio of now-patched security issues in TorchServe, an open-source tool for scaling PyTorch machine-learning models in production, could lead to server takeover and remote code execution (RCE), according to security researchers. The three CVEs, collectively dubbed "ShellTorch," rendered "tens of thousands of exposed instances" vulnerable, wrote software bill of material management firm Oligo Security's Idan Levcovich, Guy Kaplan, and Gal Elbaz in a report published on Tuesday. Meta, which along...