The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2019-12-11 19:15
Updated : 2023-02-28 07:12
NVD link : CVE-2017-18640
Mitre link : CVE-2017-18640
JSON object : View
CWE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Products Affected
snakeyaml_project
- snakeyaml
oracle
- peoplesoft_enterprise_pt_peopletools
quarkus
- quarkus
fedoraproject
- fedora