Wow. Genau so sollte man als Library-Entwickler mit ernsthaften Sicherheitslücken nicht umgehen. https://bitbucket.org/snakeyaml/snakeyaml/commits/5735ec7ca65a68da96083c34accbffb4fa0985b3 #snakeyaml #security
RT @BrianVerm@twitter.com
SnakeYaml, a YAML parser and emitter for Java, has a vulnerability that allows arbitrary code execution. The flaw in its Constructor class doesn't restrict deserialized types. Learn more about this vulnerability: https://buff.ly/3iQxvqy
#Java #SnakeYaml #securityvulnerability
🐦🔗: https://twitter.com/BrianVerm/status/1602954048080158721
#java #SnakeYAML #securityvulnerability
SnakeYaml, a YAML parser and emitter for Java, has a vulnerability that allows arbitrary code execution. The flaw in its Constructor class doesn't restrict deserialized types. Learn more about this vulnerability: https://t.co/iPENynt41h
#Java #SnakeYaml #securityvulnerability https://t.co/3Kbq1IaZM3
#java #SnakeYAML #securityvulnerability