CVE-2022-38752
Summary
| CVE | CVE-2022-38752 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-05 10:15:00 UTC |
| Updated | 2024-03-15 11:15:00 UTC |
| Description | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| snakeyaml: Multiple Vulnerabilities (GLSA 202305-28) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| security.netapp.com/advisory/ntap-20240315-0009 |
|
security.netapp.com |
|
| 47081 -
oss-fuzz -
OSS-Fuzz: Fuzzing the planet -
Monorail |
MISC |
bugs.chromium.org |
|
| snakeyaml / snakeyaml
/ issues
/ #531 - Stackoverflow [OSS-Fuzz - 47081]
— Bitbucket |
MISC |
bitbucket.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182585 Debian Security Update for snakeyaml (CVE-2022-38752)
- 20396 IBM DB2 Multiple Vulnerabilities (7095807)
- 241301 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 7 (RHSA-2023:1512)
- 241302 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 8 (RHSA-2023:1513)
- 241303 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 9 (RHSA-2023:1514)
- 241405 Red Hat Update for Satellite 6.13 (RHSA-2023:2097)
- 356386 Amazon Linux Security Advisory for snakeyaml : ALAS2023-2023-375
- 357078 Amazon Linux Security Advisory for snakeyaml : ALAS2-2024-2450
- 710729 Gentoo Linux snakeyaml Multiple Vulnerabilities (GLSA 202305-28)
- 753357 SUSE Enterprise Linux Security Update for snakeyaml (SUSE-SU-2022:3397-1)
- 904055 Common Base Linux Mariner (CBL-Mariner) Security Update for snakeyaml (11026)
- 960924 Rocky Linux Security Update for Satellite (RLSA-2023:2097)