Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to SnakeYAML to address CVE-2017-18640 #3228

Merged
merged 1 commit into from
Apr 4, 2020

Conversation

joschi
Copy link
Member

@joschi joschi commented Apr 4, 2020

SnakeYAML < 1.26 is vulnerable to a Billion Laughs attack (denial of service).

Refs FasterXML/jackson-dataformats-text#187
Refs #3223

@joschi joschi added the security label Apr 4, 2020
@joschi joschi added this to the 2.0.6 milestone Apr 4, 2020
@joschi joschi requested a review from a team April 4, 2020 13:50
@joschi joschi self-assigned this Apr 4, 2020
@joschi joschi merged commit 9587649 into master Apr 4, 2020
@joschi joschi deleted the snakeyaml-1.26-cve-2017-18640 branch April 4, 2020 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants