Security update for snakeyaml
This update for snakeyaml fixes the following issues: - CVE-2022-38750: Fixed uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (bsc#1203158). - CVE-2022-38749: Fixed StackOverflowError for many open unmatched brackets (bsc#1203149). - CVE-2022-38752: Fixed uncaught exception in java.base/java.util.ArrayList.hashCode (bsc#1203154). - CVE-2022-38751: Fixed unrestricted data matched with Regular Expressions (bsc#1203153). - CVE-2022-25857: Fixed denial of service vulnerability due missing to nested depth limitation for collections (bsc#1202932).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for snakeyaml fixes the following issues: - CVE-2022-38750: Fixed uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (bsc#1203158). - CVE-2022-38749: Fixed StackOverflowError for many open unmatched brackets (bsc#1203149). - CVE-2022-38752: Fixed uncaught exception in java.base/java.util.ArrayList.hashCode (bsc#1203154). - CVE-2022-38751: Fixed unrestricted data matched with Regular Expressions (bsc#1203153). - CVE-2022-25857: Fixed denial of service vulnerability due missing to nested depth limitation for collections (bsc#1202932).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1202932
- https://bugzilla.suse.com/1203149
- https://bugzilla.suse.com/1203153
- https://bugzilla.suse.com/1203154
- https://bugzilla.suse.com/1203158
- https://www.suse.com/security/cve/CVE-2020-13936
- https://www.suse.com/security/cve/CVE-2022-25857
- https://www.suse.com/security/cve/CVE-2022-38749
- https://www.suse.com/security/cve/CVE-2022-38750
- https://www.suse.com/security/cve/CVE-2022-38751
- https://www.suse.com/security/cve/CVE-2022-38752
- https://www.suse.com/support/update/announcement/2022/suse-su-20223397-1/