Skip to content

[FP]: SnakeYAML 1.32 is no longer affected by CVE-2022-38725 #4839

@kwin

Description

@kwin

Package URl

pkg:maven/org.yaml/[email protected]

CPE

cpe:2.3:a:snakeyaml_project:snakeyaml:1.32:::::::*

CVE

CVE-2022-38752

ODC Integration

{"label"=>"Maven Plugin"}

ODC Version

7.1.0

Description

There is no version range included in https://nvd.nist.gov/vuln/detail/CVE-2022-38752. But although the underlying issue https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081 was fixed in 1.32 this version is still reported as being affected.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions