-
-
Notifications
You must be signed in to change notification settings - Fork 942
Closed
Milestone
Description
jruby-complete 9.3.8.0 embeds a version of snakeyaml at ./META-INF/jruby.home/lib/ruby/stdlib/org/yaml/snakeyaml/ that is subject to CVE-2022-38751
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
Upgrade to 1.32 or later.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels