Bugzilla – Bug 1202932
VUL-0: CVE-2022-25857: snakeyaml: snakeyaml vulnerable to DoS due missing to nested depth limitation for collections
Last modified: 2022-12-20 11:22:49 UTC
CVE-2022-25857 The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-25857 https://www.cve.org/CVERecord?id=CVE-2022-25857 https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174 https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174 https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360 https://bitbucket.org/snakeyaml/snakeyaml/issues/525
Affected: - SUSE:SLE-15-SP2:Update/snakeyaml 1.28 - SUSE:SLE-15-SP2:Update:Products:Manager41:Update/snakeyaml 1.28 - openSUSE:Factory/snakeyaml 1.28
SUSE-SU-2022:3397-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1202932,1203149,1203153,1203154,1203158 CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752 JIRA References: Sources used: openSUSE Leap 15.4 (src): snakeyaml-1.31-150200.3.8.1 openSUSE Leap 15.3 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for SUSE Manager Server 4.3 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for SUSE Manager Server 4.2 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): snakeyaml-1.31-150200.3.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3560-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1183360,1202932,1203149,1203153,1203154,1203158 CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752 JIRA References: Sources used: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (src): snakeyaml-1.31-150200.12.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done