Junglewise Threat Intelligence

CVE-2022-38749: snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write

CVE-2022-38749 · Severity: low · CVSS 3.1 · Published 2022-09-06

Technologies: org.yaml:snakeyaml (Maven). Vendors: Maven.

Executive brief

snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write

Affected products

  • Maven pl.droidsonroids.yaml:snakeyaml
  • Maven be.cylab:snakeyaml
  • Maven org.testifyproject.external:external-snakeyaml
  • Maven io.prometheus.jmx:jmx_prometheus_httpserver_java6
  • Maven org.yaml:snakeyaml
  • Maven io.prometheus.jmx:jmx_prometheus_httpserver
  • Maven com.alipay.sofa.acts:acts-common-util

Related threats