The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Snakeyaml | Snakeyaml_project | * | 1.26 (excluding) |
Red Hat AMQ Streams 1.8.0 | RedHat | prometheus-jmx-exporter | * |
Red Hat build of Quarkus 1.3.4 | RedHat | snakeyaml | * |
Red Hat Enterprise Linux 8 | RedHat | prometheus-jmx-exporter-0:0.12.0-6.el8 | * |
Red Hat Fuse 7.9 | RedHat | prometheus-jmx-exporter | * |
Snakeyaml | Ubuntu | bionic | * |
Snakeyaml | Ubuntu | disco | * |
Snakeyaml | Ubuntu | eoan | * |
Snakeyaml | Ubuntu | groovy | * |
Snakeyaml | Ubuntu | hirsute | * |
Snakeyaml | Ubuntu | impish | * |
Snakeyaml | Ubuntu | kinetic | * |
Snakeyaml | Ubuntu | lunar | * |
Snakeyaml | Ubuntu | mantic | * |
Snakeyaml | Ubuntu | trusty | * |
Snakeyaml | Ubuntu | xenial | * |