The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Snakeyaml | Snakeyaml_project | * | 1.31 (excluding) |
AMQ Clients | RedHat | snakeyaml | * |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-2-plugins-0:4.12.1698294000-1.el8 | * |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-2-plugins-0:4.12.1706515741-1.el8 | * |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-2-plugins-0:4.13.1698292274-1.el8 | * |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-2-plugins-0:4.13.1706516346-1.el8 | * |
OCP-Tools-4.14-RHEL-8 | RedHat | jenkins-2-plugins-0:4.14.1699356715-1.el8 | * |
OCP-Tools-4.14-RHEL-8 | RedHat | jenkins-2-plugins-0:4.14.1706516441-1.el8 | * |
OpenShift Developer Tools and Services for OCP 4.11 | RedHat | jenkins-2-plugins-0:4.11.1683009941-1.el8 | * |
Red Hat AMQ Broker 7 | RedHat | snakeyaml | * |
Red Hat build of Eclipse Vert.x 4.3.3 | RedHat | snakeyaml | * |
Red Hat build of Quarkus Platform 2.7.6.SP1 | RedHat | snakeyaml | * |
Red Hat Data Grid 8.4.0 | RedHat | snakeyaml | * |
Red Hat Enterprise Linux 8 | RedHat | prometheus-jmx-exporter-0:0.12.0-8.el8_6 | * |
Red Hat Fuse 7.11.1 | RedHat | snakeyaml | * |
Red Hat JBoss Enterprise Application Platform 7 | RedHat | snakeyaml | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-snakeyaml-0:1.31.0-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-snakeyaml-0:1.31.0-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | RedHat | eap7-snakeyaml-0:1.31.0-1.redhat_00001.1.el7eap | * |
Red Hat OpenShift Container Platform 4.10 | RedHat | jenkins-2-plugins-0:4.10.1675144701-1.el8 | * |
Red Hat OpenShift Container Platform 4.9 | RedHat | jenkins-2-plugins-0:4.9.1675668922-1.el8 | * |
Red Hat Satellite 6.13 for RHEL 8 | RedHat | candlepin-0:4.2.13-1.el8sat | * |
Red Hat Single Sign-On 7 | RedHat | snakeyaml | * |
Red Hat Single Sign-On 7.6 for RHEL 7 | RedHat | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso | * |
Red Hat Single Sign-On 7.6 for RHEL 8 | RedHat | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso | * |
Red Hat Single Sign-On 7.6 for RHEL 9 | RedHat | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso | * |
RHEL-8 based Middleware Containers | RedHat | rh-sso-7/sso76-openshift-rhel8:7.6-20 | * |
RHINT Camel-Springboot 3.18.3.P2 | RedHat | snakeyaml | * |
RHINT Camel-Springboot 3.20.1 | RedHat | snakeyaml | * |
RHINT Service Registry 2.3.0 GA | RedHat | snakeyaml | * |
RHPAM 7.13.4 async | RedHat | snakeyaml | * |
Snakeyaml | Ubuntu | bionic | * |
Snakeyaml | Ubuntu | esm-apps/xenial | * |
Snakeyaml | Ubuntu | focal | * |
Snakeyaml | Ubuntu | jammy | * |
Snakeyaml | Ubuntu | kinetic | * |
Snakeyaml | Ubuntu | trusty | * |
Snakeyaml | Ubuntu | trusty/esm | * |
Snakeyaml | Ubuntu | xenial | * |