CVE Vulnerabilities

CVE-2022-25857

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Published: Aug 30, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

Weakness

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Affected Software

NameVendorStart VersionEnd Version
SnakeyamlSnakeyaml_project*1.31 (excluding)
AMQ ClientsRedHatsnakeyaml*
OCP-Tools-4.12-RHEL-8RedHatjenkins-2-plugins-0:4.12.1698294000-1.el8*
OCP-Tools-4.12-RHEL-8RedHatjenkins-2-plugins-0:4.12.1706515741-1.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-2-plugins-0:4.13.1698292274-1.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-2-plugins-0:4.13.1706516346-1.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-2-plugins-0:4.14.1699356715-1.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-2-plugins-0:4.14.1706516441-1.el8*
OpenShift Developer Tools and Services for OCP 4.11RedHatjenkins-2-plugins-0:4.11.1683009941-1.el8*
Red Hat AMQ Broker 7RedHatsnakeyaml*
Red Hat build of Eclipse Vert.x 4.3.3RedHatsnakeyaml*
Red Hat build of Quarkus Platform 2.7.6.SP1RedHatsnakeyaml*
Red Hat Data Grid 8.4.0RedHatsnakeyaml*
Red Hat Enterprise Linux 8RedHatprometheus-jmx-exporter-0:0.12.0-8.el8_6*
Red Hat Fuse 7.11.1RedHatsnakeyaml*
Red Hat JBoss Enterprise Application PlatformRedHatorg.yaml/snakeyaml:1.31.0.redhat-00001*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-activemq-artemis-0:1.5.5.016-1.redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-artemis-native-1:1.5.5.016-1.redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jboss-xnio-base-0:3.5.11-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jsoup-0:1.14.2-1.redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-undertow-0:1.4.18-14.SP13_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-0:7.1.10-2.GA_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-woodstox-core-0:5.0.3-2.redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-xml-security-0:2.0.10-2.redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-activemq-artemis-0:2.9.0-10.redhat_00021.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-gson-0:2.8.9-1.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-hal-console-0:3.2.18-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-server-migration-0:1.7.2-14.Final_redhat_00015.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-xnio-base-0:3.7.14-3.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-wildfly-0:7.3.13-4.GA_redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-woodstox-core-0:6.4.0-1.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-snakeyaml-0:1.31.0-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-snakeyaml-0:1.31.0-1.redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-snakeyaml-0:1.31.0-1.redhat_00001.1.el7eap*
Red Hat OpenShift Container Platform 4.10RedHatjenkins-2-plugins-0:4.10.1675144701-1.el8*
Red Hat OpenShift Container Platform 4.9RedHatjenkins-2-plugins-0:4.9.1675668922-1.el8*
Red Hat Satellite 6.13 for RHEL 8RedHatcandlepin-0:4.2.13-1.el8sat*
Red Hat Single Sign-On 7RedHatsnakeyaml*
Red Hat Single Sign-On 7.6 for RHEL 7RedHatrh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso*
Red Hat Single Sign-On 7.6 for RHEL 8RedHatrh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso76-openshift-rhel8:7.6-20*
RHINT Camel-Springboot 3.18.3.P2RedHatsnakeyaml*
RHINT Camel-Springboot 3.20.1RedHatsnakeyaml*
RHINT Service Registry 2.3.0 GARedHatsnakeyaml*
RHPAM 7.13.4 asyncRedHatsnakeyaml*
SnakeyamlUbuntubionic*
SnakeyamlUbuntuesm-apps/bionic*
SnakeyamlUbuntuesm-apps/focal*
SnakeyamlUbuntuesm-apps/jammy*
SnakeyamlUbuntuesm-apps/xenial*
SnakeyamlUbuntuesm-infra-legacy/trusty*
SnakeyamlUbuntufocal*
SnakeyamlUbuntujammy*
SnakeyamlUbuntukinetic*
SnakeyamlUbuntutrusty*
SnakeyamlUbuntutrusty/esm*
SnakeyamlUbuntuxenial*

Potential Mitigations

References