Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability CVE-2022-1471 for snakeyaml@1.33 #2532

Closed
amahfouz1 opened this issue Jan 24, 2023 · 1 comment
Closed

Security Vulnerability CVE-2022-1471 for snakeyaml@1.33 #2532

amahfouz1 opened this issue Jan 24, 2023 · 1 comment

Comments

@amahfouz1
Copy link

Describe the bug
CVE-2022-1471

Client Version
17.0.0

Kubernetes Version
N/A

Java Version
Java 11

To Reproduce
Security Vulnerability CVE-2022-1471 for snakeyaml@1.33

Expected behavior
Upgrade to a snakeyaml version > 1.33 addressing CVE-2022-1471

KubeConfig
If applicable, add a KubeConfig file with secrets redacted.

Server (please complete the following information):
Linux

Additional context
Add any other context about the problem here.

@brendandburns
Copy link
Contributor

#2533 fixes this and releases (17.0.1, 16.0.3 & 15.0.2) have the patch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants