Lucene search

K
f5F5F5:K000132638
HistoryFeb 16, 2023 - 12:00 a.m.

K000132638 : SnakeYAML vulnerability CVE-2022-1471

2023-02-1600:00:00
my.f5.com
15
snakeyaml
constructor()
vulnerability
cve-2022-1471
deserialization
remote code execution
safeconstructor
f5 products

AI Score

7.7

Confidence

Low

EPSS

0.021

Percentile

89.3%

Security Advisory Description

SnakeYaml’s Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml’s SafeConsturctor when parsing untrusted content to restrict deserialization. (CVE-2022-1471)

Impact

There is no impact; F5 products are not affected by this vulnerability.