QID 980876
QID 980876: Dotnet (nuget) Security Update for YamlDotNet.Signed (GHSA-rpch-cqj9-h65r)
YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can result in Code execution in the context of the running process. This attack appear to be exploitable via Victim must parse a specially-crafted YAML file. This vulnerability appears to have been fixed in 5.0.0.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rpch-cqj9-h65r for updates pertaining to this vulnerability.
Vendor References
- GHSA-rpch-cqj9-h65r -
github.com/advisories/GHSA-rpch-cqj9-h65r
CVEs related to QID 980876
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rpch-cqj9-h65r | YamlDotNet |
|
|
| GHSA-rpch-cqj9-h65r | YamlDotNet.Signed |
|