Uploaded image for project: 'TinkerPop'
  1. TinkerPop
  2. TINKERPOP-2894

Need upgrade to snakeyaml 1.3.4 or later

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Duplicate
    • 3.6.2
    • None
    • server

    Description

      snakeyaml-1.3.2 is causing the following vulerability...

      SnakeYaml Constructor Deserialization Remote Code Execution

      https://github.com/advisories/GHSA-mjmj-j48q-9wg2

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              jfoscue Jim Foscue
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: