Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38321
HistoryDec 02, 2022 - 5:22 p.m.

Remote Code Execution (RCE)

2022-12-0217:22:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
snakeyaml vulnerability
remote code execution
classpath injection
deserialization

0.022 Low

EPSS

Percentile

89.4%

SnakeYaml is vulnerable to Remote Code Execution (RCE). The vulnerability is due to deserializing unrestricted types in the Constructor method leading to Remote Code execution through classpath injection.

References