Foojay.io · @foojay
680 followers · 487 posts · Server foojay.social

In December of last year, reported on CVE-2022-1471 about 2.0. This unsafe deserialization problem could easily lead to arbitrary code execution under the right circumstances. @brianverm provides solutions on Foojay :foojay: Today:

foojay.io/today/snakeyaml-2-0-

#snyk #snakeyaml #foojaytip

Last updated 1 year ago

Foojay.io · @foojay
439 followers · 144 posts · Server foojay.social

is a well-known 1.1 parser and emitter for , by default in the spring-boot-starter. Recently, a vulnerability was reported for this package. This vulnerability can lead to arbitrary code execution. @brianverm from to the rescue on Foojay :foojay: Today!

foojay.io/today/unsafe-deseria

#snakeyaml #yaml #java #snyk #foojaytip

Last updated 2 years ago

Mark Derricutt (talios) · @talios
679 followers · 1372 posts · Server mastodon.nz

Reading the tone of the back’n’forth in this issue thread is painful to read: bitbucket.org/snakeyaml/snakey
When you see the resolution came about from a voice-to-voice call - and a smaller scoped, easier to implement solution, that was deemed acceptable to all involved presented itself - it’s good to remember that sometimes…. meetings are good.
Hopefully SnakeYaml 2.0 gets released sooner than the biannual February date.

#snakeyaml #security

Last updated 2 years ago

Liran Tal :verified: · @lirantal
267 followers · 184 posts · Server infosec.exchange

🚨 SnakeYaml, a YAML parser and emitter for Java, has a vulnerability that allows arbitrary code execution.

The flaw in its Constructor class doesn't restrict deserialized types. Learn more about this vulnerability: buff.ly/3iQxvqy

#java #snakeyaml #vulnerability #cve

Last updated 2 years ago

Liran Tal · @lirantal
104 followers · 21 posts · Server infosec.exchange

⚠️ A vulnerability for , a well-known 1.1 parser and emitter for , was recently reported snyk.io/blog/unsafe-deserializ

Learn how CVE-2022-1471 can lead to arbitrary code execution and how best to mitigate it from
@brianverm

#snakeyaml #yaml #java

Last updated 2 years ago