CVE-2022-41854: Stack Overflow in Snakeyaml
Stack Overflow in Snakeyaml
Other sources
Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/eap7-snakeyamlto a version that resolves this vulnerability.Fixed in 0:1.33.0-2.SP1_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-snakeyamlto a version that resolves this vulnerability.Fixed in 0:1.33.0-2.SP1_redhat_00001.1.el9ea - Upgrade
Upgrade
redhat/eap7-snakeyamlto a version that resolves this vulnerability.Fixed in 0:1.33.0-2.SP1_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.7-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.7-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.7-1.redhat_00001.1.el9 - Upgrade
Upgrade
maven/org.yaml:snakeyamlto a version that resolves this vulnerability.Fixed in 1.32 - Upgrade
Upgrade
redhat/snakeyamlto a version that resolves this vulnerability.Fixed in 1.32
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-41854?
CVE-2022-41854 is a vulnerability in snakeYAML that allows for a denial of service attack through improper input validation.
What is the severity of CVE-2022-41854?
The severity of CVE-2022-41854 is medium, with a CVSS score of 6.5.
How does CVE-2022-41854 affect Snakeyaml users?
Snakeyaml users who parse untrusted YAML files may be vulnerable to denial of service attacks.
How can the CVE-2022-41854 vulnerability be fixed?
To fix the CVE-2022-41854 vulnerability, users should update to snakeYAML version 1.33.0 or later.
Are there any references for CVE-2022-41854?
Yes, you can find more information about CVE-2022-41854 in the following references: [link1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50355) and [link2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2152478).