Critical
Low
Medium

CVE-2022-1471 — SnakeYAML Deserialization RCE

Overview

Critical
Low
Medium
No items found.

Package: org.yaml:snakeyaml

Impact: Remote code execution via unsafe YAML deserialization

Fix: Update to SnakeYAML v2.0+

Year: 2022

CVSS: 9.8

Severity: Critical

Affected Components

Location

* src/main/java/org/yaml/snakeyaml/constructor/Constructor.java

* protected Class<?> getClassForNode(Node node)

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo