SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-prometheus-jmx-exporteralma-upgrade-prometheus-jmx-exporter-openjdk11alma-upgrade-prometheus-jmx-exporter-openjdk17alma-upgrade-prometheus-jmx-exporter-openjdk8 | Dec 19, 2022 | Dec 1, 2022 | |
| Atlassian Bitbucket | atlassian-bitbucket-upgrade-latest | Nov 14, 2024 | Dec 6, 2023 | |
| Atlassian Jira | atlassian-jira-upgrade-latest | Apr 21, 2026 | Dec 6, 2023 | |
| Centos_linux | — | centos-upgrade-foreman-clicentos-upgrade-prometheus-jmx-exportercentos-upgrade-prometheus-jmx-exporter-openjdk11centos-upgrade-prometheus-jmx-exporter-openjdk17centos-upgrade-prometheus-jmx-exporter-openjdk8centos-upgrade-python39-pulp_manifestcentos-upgrade-rubygem-amazing_printcentos-upgrade-rubygem-apipie-bindingscentos-upgrade-rubygem-clampcentos-upgrade-rubygem-domain_namecentos-upgrade-rubygem-fast_gettextcentos-upgrade-rubygem-fficentos-upgrade-rubygem-ffi-debuginfocentos-upgrade-rubygem-ffi-debugsourcecentos-upgrade-rubygem-foreman_maintaincentos-upgrade-rubygem-gssapicentos-upgrade-rubygem-hammer_clicentos-upgrade-rubygem-hammer_cli_foremancentos-upgrade-rubygem-hammer_cli_foreman_admincentos-upgrade-rubygem-hammer_cli_foreman_ansiblecentos-upgrade-rubygem-hammer_cli_foreman_azure_rmcentos-upgrade-rubygem-hammer_cli_foreman_bootdiskcentos-upgrade-rubygem-hammer_cli_foreman_discoverycentos-upgrade-rubygem-hammer_cli_foreman_googlecentos-upgrade-rubygem-hammer_cli_foreman_openscapcentos-upgrade-rubygem-hammer_cli_foreman_remote_executioncentos-upgrade-rubygem-hammer_cli_foreman_taskscentos-upgrade-rubygem-hammer_cli_foreman_templatescentos-upgrade-rubygem-hammer_cli_foreman_virt_who_configurecentos-upgrade-rubygem-hammer_cli_foreman_webhookscentos-upgrade-rubygem-hammer_cli_katellocentos-upgrade-rubygem-hashiecentos-upgrade-rubygem-highlinecentos-upgrade-rubygem-http-acceptcentos-upgrade-rubygem-http-cookiecentos-upgrade-rubygem-jwtcentos-upgrade-rubygem-little-pluggercentos-upgrade-rubygem-localecentos-upgrade-rubygem-loggingcentos-upgrade-rubygem-mime-typescentos-upgrade-rubygem-mime-types-datacentos-upgrade-rubygem-multi_jsoncentos-upgrade-rubygem-netrccentos-upgrade-rubygem-oauthcentos-upgrade-rubygem-oauth-ttycentos-upgrade-rubygem-powerbarcentos-upgrade-rubygem-rest-clientcentos-upgrade-rubygem-snaky_hashcentos-upgrade-rubygem-unfcentos-upgrade-rubygem-unf_extcentos-upgrade-rubygem-unf_ext-debuginfocentos-upgrade-rubygem-unf_ext-debugsourcecentos-upgrade-rubygem-unicodecentos-upgrade-rubygem-unicode-debuginfocentos-upgrade-rubygem-unicode-debugsourcecentos-upgrade-rubygem-unicode-display_widthcentos-upgrade-rubygem-version_gemcentos-upgrade-satellite-clicentos-upgrade-satellite-clonecentos-upgrade-satellite-maintain | Dec 16, 2022 | Dec 1, 2022 |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Dec 1, 2022 | |
| Dell Powerstore Dsa2023366 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Oct 5, 2023 | |
| Dell Powerstore Dsa2025182 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Apr 17, 2025 | |
| Oracle_linux | — | oracle-linux-upgrade-prometheus-jmx-exporteroracle-linux-upgrade-prometheus-jmx-exporter-openjdk11oracle-linux-upgrade-prometheus-jmx-exporter-openjdk17oracle-linux-upgrade-prometheus-jmx-exporter-openjdk8 | Dec 16, 2022 | Oct 13, 2022 |
| Red Hat Jboss Eap | red-hat-jboss-eap-upgrade-latest | Sep 19, 2024 | Oct 13, 2022 | |
| Redhat Openshift | linuxrpm-upgrade-jenkins-2-plugins | Feb 16, 2023 | Dec 1, 2022 | |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-prometheus-jmx-exporterredhat-upgrade-prometheus-jmx-exporter-openjdk11redhat-upgrade-prometheus-jmx-exporter-openjdk17redhat-upgrade-prometheus-jmx-exporter-openjdk8 | Dec 16, 2022 | Dec 1, 2022 | |
| Rocky_linux | rocky-upgrade-libdb-cxxrocky-upgrade-libdb-cxx-debuginforocky-upgrade-libdb-debuginforocky-upgrade-libdb-debugsourcerocky-upgrade-libdb-sql-debuginforocky-upgrade-libdb-sql-devel-debuginforocky-upgrade-libdb-utils-debuginfo | Mar 12, 2024 | Dec 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub