CVE-2022-1471

CVE-2022-1471

SnakeYaml’s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml’s SafeConsturctor when parsing untrusted content to restrict deserialization.

Source: CVE-2022-1471

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다