Uncontrolled Resource Consumption in snakeyaml
High severity
GitHub Reviewed
Published
Aug 31, 2022
to the GitHub Advisory Database
•
Updated Mar 15, 2024
Description
Published by the National Vulnerability Database
Aug 30, 2022
Published to the GitHub Advisory Database
Aug 31, 2022
Reviewed
Sep 9, 2022
Last updated
Mar 15, 2024
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
References