Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-41854 impacting snakeyaml 1.29 #114

Open
arcadmlafon opened this issue Nov 23, 2022 · 1 comment
Open

CVE-2022-41854 impacting snakeyaml 1.29 #114

arcadmlafon opened this issue Nov 23, 2022 · 1 comment
Milestone

Comments

@arcadmlafon
Copy link

Hi, thanks for this great editor,

I know that in the context of a text editor, this problem may be ignored but just for information there is a vulnerability declared on snakeyaml which may cause application crash depending on the origin of the yaml source. An upgrade to version 1.32 should be great.

See https://nvd.nist.gov/vuln/detail/CVE-2022-41854 for details.

@de-jcup
Copy link
Owner

de-jcup commented Mar 27, 2023

Thanks for reporting

Remark: the markdown editor of github does strange things with links to NIST... the origin link above does not target NIST page but instead https://github.com/de-jcup/eclipse-yaml-editor/issues/CVE-2022-41854 which points to nothing...

Seems to be a bug.

@de-jcup de-jcup added this to the 1.10.0 milestone Mar 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants