Information on source package snakeyaml

Available versions

ReleaseVersion
jessie1.12-2+deb8u1
stretch1.17-1+deb9u1
buster1.23-1+deb10u1
bullseye1.28-1+deb11u2
bookworm1.33-2
trixie1.33-2
sid1.33-2

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2017-18640vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedfixedThe Alias feature in SnakeYAML before 1.26 allows entity expansion dur ...

Open unimportant issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2022-41854fixedfixedfixedvulnerablefixedfixedfixedThose using Snakeyaml to parse untrusted YAML files may be vulnerable ...
CVE-2022-38752vulnerablevulnerablevulnerablevulnerablefixedfixedfixedUsing snakeYAML to parse untrusted YAML files may be vulnerable to Den ...
CVE-2022-1471vulnerablevulnerablevulnerablevulnerablevulnerablevulnerablevulnerableSnakeYaml's Constructor() class does not restrict types which can be i ...

Resolved issues

BugDescription
CVE-2022-38751Using snakeYAML to parse untrusted YAML files may be vulnerable to Den ...
CVE-2022-38750Using snakeYAML to parse untrusted YAML files may be vulnerable to Den ...
CVE-2022-38749Using snakeYAML to parse untrusted YAML files may be vulnerable to Den ...
CVE-2022-25857The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable t ...

Security announcements

DSA / DLADescription
ELA-693-1snakeyaml - security update
DLA-3132-1snakeyaml - security update

Search for package or bug name: Reporting problems