gpp_maybe
Security update for snakeyaml
SUSE-SLE-Module-Development-Tools-15-SP3-2022-3397
This update for snakeyaml fixes the following issues: - CVE-2022-38750: Fixed uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (bsc#1203158). - CVE-2022-38749: Fixed StackOverflowError for many open unmatched brackets (bsc#1203149). - CVE-2022-38752: Fixed uncaught exception in java.base/java.util.ArrayList.hashCode (bsc#1203154). - CVE-2022-38751: Fixed unrestricted data matched with Regular Expressions (bsc#1203153). - CVE-2022-25857: Fixed denial of service vulnerability due missing to nested depth limitation for collections (bsc#1202932).
-
Release DateSep 26 2022
-
ReferencesBugzilla: 1203158, 1203149, 1203154, 1203153, 1202932
CVEs: CVE-2020-13936, CVE-2022-25857, CVE-2022-38751, CVE-2022-38749, CVE-2022-38750, CVE-2022-38752 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.3 x86_64
-
Packagessnakeyaml
YAML parser and emitter for the Java programming language1.31-150200.3.8.1 lock rpm lock src
Development Tools Module 15.3 aarch64
-
Packagessnakeyaml
YAML parser and emitter for the Java programming language1.31-150200.3.8.1 lock rpm lock src
Development Tools Module 15.3 s390x
-
Packagessnakeyaml
YAML parser and emitter for the Java programming language1.31-150200.3.8.1 lock rpm lock src
Development Tools Module 15.3 ppc64le
-
Packagessnakeyaml
YAML parser and emitter for the Java programming language1.31-150200.3.8.1 lock rpm lock src