VulnerabilityModified
CVE-2022-38752
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS).
MEDIUM 6.5EPSS 2.53%
Does this matter?
Lower severity and a low EPSS score (2.53%). Track it; it rarely justifies an emergency change on its own.
Description
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.53% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-787
- Affected
- snakeyaml project/snakeyaml
- Source
- cve-coordination@google.com
References
- https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081Third Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081Permissions Required
- https://security.gentoo.org/glsa/202305-28
- https://security.netapp.com/advisory/ntap-20240315-0009/
- https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081Third Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081Permissions Required
- https://security.gentoo.org/glsa/202305-28
- https://security.netapp.com/advisory/ntap-20240315-0009/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.