You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
A clear and concise description of what the bug is. We won't be able to help you without propper information to reproduce the bug. (please add links, sources etc if applicable)
Screenshots
If applicable, add screenshots to help explain your problem.
Desktop (please complete the following information):
Plugin Version: [eg, 6.3.2]
Server Version: [eg, Paper spigot 1.12.2]
Web client used: [client.openaudiomc.net (default)]
Other setup details: [please note if you use bungeecord or run your server in offlinemode, remove otherwise]
Additional context
Hi, In /module-src/vistas-server,there is a dependency org.yaml:snakeyaml:1.29 that calls the risk method.
The scope of this CVE affected version is ** [0,1.31)**
After further analysis, in this project, the main Api called is org.yaml.snakeyaml.composer.Composer: composeNode(org.yaml.snakeyaml.nodes.Node)Lorg.yaml.snakeyaml.nodes.Node;
Describe the bug
A clear and concise description of what the bug is. We won't be able to help you without propper information to reproduce the bug. (please add links, sources etc if applicable)
Screenshots
If applicable, add screenshots to help explain your problem.
Desktop (please complete the following information):
Additional context
Hi, In /module-src/vistas-server,there is a dependency org.yaml:snakeyaml:1.29 that calls the risk method.
CVE-2022-25857
The scope of this CVE affected version is ** [0,1.31)**
After further analysis, in this project, the main Api called is org.yaml.snakeyaml.composer.Composer: composeNode(org.yaml.snakeyaml.nodes.Node)Lorg.yaml.snakeyaml.nodes.Node;
Risk method repair link : GitHub
CVE Bug Invocation Path--
Path Length : 7
Dependency tree--
Suggested solutions:
Update dependency version
Thank you very much.
The text was updated successfully, but these errors were encountered: