CVE-2022-1471

Scores

EPSS

0.938High
93.8%
0%20%40%60%80%100%

Percentile: 93.8%

CVSS

9.8Critical
3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

SnakeYaml’s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml’s SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-20CWE-502

Exploits

Exploit ID: CVE-2022-1471

Source: github-poc

URL: https://github.com/1fabunicorn/SnakeYAML-CVE-2022-1471-POC

Vulnerable Software (20)

Type: Configuration

Product: candlepin

Operating System: rhel

Trait:
{
  "fixed": "4.2.13-1.el8sat"
}

Source: redhat

Type: Configuration

Product: eap7-snakeyaml

Operating System: rhel

Trait:
{
  "fixed": "1.33.0-2.SP1_redhat_00001.1.el8eap"
}

Source: redhat

Type: Configuration

Product: eap7-snakeyaml

Operating System: rhel

Trait:
{
  "fixed": "1.33.0-2.SP1_redhat_00001.1.el7eap"
}

Source: redhat

Type: Configuration

Product: eap7-snakeyaml

Operating System: rhel

Trait:
{
  "fixed": "1.33.0-2.SP1_redhat_00001.1.el9eap"
}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{
  "fixed": "4.9.1675668922-1.el8"
}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{
  "fixed": "4.10.1675407676-1.el8"
}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{
  "fixed": "4.11.1706516946-1.el8"
}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{
  "fixed": "4.11.1698299029-1.el8"
}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{
  "fixed": "4.11.1683009941-1.el8"
}

Source: redhat

Type: Configuration

Product: prometheus-jmx-exporter

Operating System: rhel

Trait:
{
  "fixed": "0.12.0-9.el8_7"
}

Source: redhat