CVE-2022-38751: DoS in SnakeYAML
A flaw was found in the snakeyaml package due to a stack-overflow in parsing YAML files. By persuading a victim to open a specially-crafted file, a remote attacker could cause the application to crash.
Other sources
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-38751?
CVE-2022-38751 is a vulnerability found in the snakeyaml package that can be exploited for Denial of Service attacks.
What is the severity of CVE-2022-38751?
The severity of CVE-2022-38751 is medium, with a CVSS score of 6.5.
How does CVE-2022-38751 affect candlepin package?
The candlepin package with version 0:4.2.13-1.el8 is affected by CVE-2022-38751.
How does CVE-2022-38751 affect rh-sso7-keycloak package?
The rh-sso7-keycloak package with versions 0:18.0.6-1.redhat_00001.1.el7, 0:18.0.6-1.redhat_00001.1.el8, and 0:18.0.6-1.redhat_00001.1.el9 are affected by CVE-2022-38751.
Is there a fix available for CVE-2022-38751?
Yes, a fix is available for CVE-2022-38751. Please refer to the Red Hat security advisory RHSA-2022:8876 for more information.