Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to snakeyaml 2.0 to fix CVE #392

Closed
olwulff opened this issue Mar 2, 2023 · 2 comments
Closed

Upgrade to snakeyaml 2.0 to fix CVE #392

olwulff opened this issue Mar 2, 2023 · 2 comments

Comments

@olwulff
Copy link

olwulff commented Mar 2, 2023

This library must be upgraded to snakeyaml 2.0 to fix the below CVE:
https://nvd.nist.gov/vuln/detail/CVE-2022-1471

@yawkat
Copy link
Member

yawkat commented Mar 2, 2023

Please see this issue: #382 – users of jackson are not affected by the CVE.

Nonetheless, we will update to 2.0 in 2.15.0: #390

@yawkat yawkat closed this as completed Mar 2, 2023
@cowtowncoder
Copy link
Member

@olwulff Please note that although we cannot (for backwards-compatibility concerns) update this for older versions, it is likely that local override of dependencies allows developers to upgrade SnakeYAML dependency too.

... despite it not being needed at all. As per @yawkat Jackson YAML module is not affected by these Vulns/CVEs at all. Yet another case of Silly Security Theater.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants