Vulnerabilities reported for snakeyaml 1.18 

Issue date: 07-04-2020
Affects versions: 14.0, 13.4, 12.6

Issue ID

SECURITY-149

 

Affected Product Version(s)

14.0.0, 13.4.2, 12.6.9 (and previous patch releases)


Severity 

Medium

Description

 

SnakeYaml reported vulnerability CVE-2017-18640 in versions for version 1.18.
The Alias feature in SnakeYAML 1.18 allows entity expansion during a load operation, a related issue to CVE-2003-1564.CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

SnakeYaml has been updated to version 1.23

Instructions

Every customer is advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.