← All CVEs

CVE-2022-1471

high · 8.3

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

8.3
CVSS
99.6%
EPSS (exploit prob.)
100th
EPSS percentile
2022-12-01
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Weaknesses

CWE-20CWE-502

Affected products

VendorProductAffected versions
snakeyaml_projectsnakeyaml< 2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-1471