-
Notifications
You must be signed in to change notification settings - Fork 6.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Markup SpringBoot users need to specify SnakeYAML version in Github Wiki #21476
Labels
Comments
|
Ok @linghengqian , I will do it. |
|
linghengqian
changed the title
Markup SpringBoot Starter users need to specify SnakeYAML version in Github Wiki
Markup SpringBoot users need to specify SnakeYAML version in Github Wiki
Dec 26, 2022
|
6 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Feature Request
For English only, other languages will not accept.
Please pay attention on issues you submitted, because we maybe need more details.
If no response anymore and we cannot make decision by current information, we will close it.
Please answer these questions before submitting your issue. Thanks!
Is your feature request related to a problem?
Describe the feature you would like.
In Update Snakeyaml to 1.33 and open YAML 3MB limit #21351, a new method for serving
LoaderOptions
introduced since SnakeYAML 1.32 is enabled. This stems from a series of CVEs that have existed since SnakeYAML 1.30 and can be traced back to [issue-15259] upgrade snakeyaml due to cve #15260 .According to CVE-2022-25857 - Upgrade to SnakeYAML 1.31 spring-projects/spring-boot#32221 , at present, Spring community ensures SnakeYAML <= 1.30 in Spring Boot OSS < 3.0.0-M5 version. Therefore, if the users of ShardingSphere JDBC use the version of SpringBoot OSS < 3.0.0-M5, they must manually specify the version of SnakeYAML in
pom.xml
and other files, similar to the following.The text was updated successfully, but these errors were encountered: