SnakeYAML Entity Expansion during load operation
High severity
GitHub Reviewed
Published
Jun 4, 2021
to the GitHub Advisory Database
•
Updated May 22, 2023
Description
Published by the National Vulnerability Database
Dec 12, 2019
Reviewed
Jun 4, 2021
Published to the GitHub Advisory Database
Jun 4, 2021
Last updated
May 22, 2023
The Alias feature in SnakeYAML 1.18 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
References