Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SUBMARINE-1371. fix unsafe deserialization via SnakeYaml in YamlEntityProvider #1054

Closed
wants to merge 3 commits into from

Conversation

cdmikechen
Copy link
Contributor

What is this PR for?

Use SnakeYaml's SafeConstructor to replace default Yaml no arguments constructor to void unsafe deserialization.
Link url: https://nvd.nist.gov/vuln/detail/CVE-2022-1471

What type of PR is it?

Bug Fix

Todos

  • - Add SafeConstructor

What is the Jira issue?

https://issues.apache.org/jira/browse/SUBMARINE-1371

How should this be tested?

NA

Screenshots (if appropriate)

Questions:

  • Do the license files need updating? Yes
  • Are there breaking changes for older versions? No
  • Does this need new documentation? No

@codecov
Copy link

codecov bot commented Mar 5, 2023

Codecov Report

Merging #1054 (5703a23) into master (5987b92) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##           master    #1054   +/-   ##
=======================================
  Coverage   75.98%   75.98%           
=======================================
  Files         119      119           
  Lines        5000     5000           
=======================================
  Hits         3799     3799           
  Misses       1201     1201           
Flag Coverage Δ
python-integration 59.72% <ø> (ø)
python-unit 52.48% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants