NA

CVE-2022-41854

Published: 11/11/2022 Updated: 15/03/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

snakeyaml project snakeyaml

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Synopsis Important: Migration Toolkit for Applications security and bug fix update Type/Severity Security Advisory: Important Topic Migration Toolkit for Applications 620 releaseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a deta ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat JBoss Enterprise Application Platform 74Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
Synopsis Critical: Red Hat Fuse 712 release and security update Type/Severity Security Advisory: Critical Topic A minor version update (from 711 to 712) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update as h ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 on RHEL 9 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 on RHEL 8 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7410 on RHEL 7 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Moderate: Red Hat build of Eclipse Vertx 437 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat build of Eclipse VertxRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a d ...
概述 Moderate: AMQ Clients 2023Q4 类型/严重性 Security Advisory: Moderate 标题 An update is now available for Red Hat AMQ ClientsRed Hat Product Security has rated this update as having an impact ofModerateA Common Vulnerability Scoring System (CVSS) base score, which gives a detailedseverity rating, is available for each vulnerabi ...
Synopsis Moderate: Red Hat Single Sign-On 763 for OpenShift image security update Type/Severity Security Advisory: Moderate Topic A new image is available for Red Hat Single Sign-On 763, running on RedHat OpenShift Container Platform from the release of 311 up to the releaseof 4120Red Hat Product Security has rated this update as havi ...
Synopsis Moderate: Red Hat Single Sign-On 763 security update on RHEL 7 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 763 packages are now available for Red Hat Enterprise Linux 7Red Hat P ...
Synopsis Important: Red Hat Integration Camel for Spring Boot 3183 Patch 2 release Type/Severity Security Advisory: Important Topic Camel for Spring Boot 3183 Patch 2 release and security update is now availableRed Hat Product Security has rated this update as having an impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Moderate: Migration Toolkit for Runtimes security update Type/Severity Security Advisory: Moderate Topic An update for mtr-operator-bundle-container, mtr-operator-container, mtr-web-container, and mtr-web-executor-container is now available for Migration Toolkit for Runtimes 1 on RHEL 8Red Hat Product Security has rated this update ...
Synopsis Moderate: Red Hat Single Sign-On 763 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base sco ...
DescriptionThe MITRE CVE dictionary describes this issue as: Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS) If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow This effect may support a denial of service attack ...

Github Repositories

Snake Yaml 的漏洞学习

Snake Yaml 的漏洞学习 CVE-2022-38752 CVE-2022-41854 一、SnakeYaml是什么 Java的一个用来处理yaml文件的库,提供了一个load方法用于加载yaml为Java对象

Spring Boot 3 and java 17 Application

bee004 Spring Boot 3 and java 17 Application Start Change the blank Git project to a a Spring Boot 3 RESTful application Use java 17 Set JDK version -> Java 17 Set Maven Vulnerabilities CVEs, that are reported vulnerabilities: CVE-2022-41854 (Out-of-bounds Write vulnerability) and CVE-2022-1471 (Deserialization of Untrusted Data vulnerability) Additional