CVE-2022-41854
Summary
| CVE | CVE-2022-41854 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-11 13:15:00 UTC |
| Updated | 2024-03-15 11:15:00 UTC |
| Description | Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 36 Update: snakeyaml-1.32-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: snakeyaml-1.32-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: picocli-4.7.4-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: snakeyaml-1.32-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 50355 -
oss-fuzz -
OSS-Fuzz: Fuzzing the planet -
Monorail |
CONFIRM |
bugs.chromium.org |
|
| security.netapp.com/advisory/ntap-20240315-0009 |
|
security.netapp.com |
|
| [SECURITY] Fedora 38 Update: picocli-4.7.4-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: snakeyaml-1.32-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181586 Debian Security Update for snakeyaml (CVE-2022-41854)
- 20396 IBM DB2 Multiple Vulnerabilities (7095807)
- 241301 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 7 (RHSA-2023:1512)
- 241302 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 8 (RHSA-2023:1513)
- 241303 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 9 (RHSA-2023:1514)
- 283543 Fedora Security Update for snakeyaml (FEDORA-2022-c01dd659fa)
- 283544 Fedora Security Update for snakeyaml (FEDORA-2022-8a4e8aa190)
- 284302 Fedora Security Update for picocli (FEDORA-2023-27ec59a486)
- 356386 Amazon Linux Security Advisory for snakeyaml : ALAS2023-2023-375
- 379452 IBM Cognos Analytics Multiple Vulnerabilities (7123154)
- 904485 Common Base Linux Mariner (CBL-Mariner) Security Update for snakeyaml (11427)