Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-18640 in SnakeYaml (transitive dependency) #3444

Open
wattdave opened this issue Feb 11, 2020 · 0 comments
Open

CVE-2017-18640 in SnakeYaml (transitive dependency) #3444

wattdave opened this issue Feb 11, 2020 · 0 comments

Comments

@wattdave
Copy link

jackson-dataformat-yaml 2.10.1 depends on SnakeYaml, all of whose versions have been reported vulnerable to CVE-2017-18640. It seems that SnakeYaml isn't going to be patched. Its author is encouraging people to move to SnakeYaml Engine instead. Jackson has started that process... https://github.com/FasterXML/jackson-dataformats-text/tree/master/yaml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant