The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
Information
                Published : 2019-12-11 19:15
Updated : 2023-02-28 07:12
NVD link : CVE-2017-18640
Mitre link : CVE-2017-18640
JSON object : View
CWE
                
                    
                        
                        CWE-776
                        
            Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Products Affected
                snakeyaml_project
- snakeyaml
oracle
- peoplesoft_enterprise_pt_peopletools
quarkus
- quarkus
fedoraproject
- fedora


