mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
933 B
933 B
CVE-2017-18640
Description
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
POC
Reference
- https://bitbucket.org/snakeyaml/snakeyaml/issues/377
- https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes
- https://www.oracle.com/security-alerts/cpuApr2021.html