5.5
CVSSv3

CVE-2023-24620

Published: 25/08/2023 Updated: 31/08/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in Esoteric YamlBeans up to and including 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and memory consumption, such as a Java Out-of-Memory exception.

Vulnerable Product Search on Vulmon Subscribe to Product

esotericsoftware yamlbeans