Vulnerability Description
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snakeyaml Project | Snakeyaml | < 1.26 |
| Fedoraproject | Fedora | 31 |
| Quarkus | Quarkus | <= 1.3.4 |
| Oracle | Peoplesoft Enterprise Pt Peopletools | 8.56 |
Related Weaknesses (CWE)
References
- https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-prevenExploitIssue TrackingPatch
- https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attackThird Party Advisory
- https://bitbucket.org/snakeyaml/snakeyaml/issues/377ExploitIssue TrackingThird Party Advisory
- https://bitbucket.org/snakeyaml/snakeyaml/wiki/ChangesRelease NotesThird Party Advisory
- https://lists.apache.org/thread.html/r1058e7646988394de6a3fd0857ea9b1ee0de14d7bb
- https://lists.apache.org/thread.html/r154090b871cf96d985b90864442d84eb027c72c94b
- https://lists.apache.org/thread.html/r16ae4e529401b75a1f5aa462b272b31bf2a108236f
- https://lists.apache.org/thread.html/r1703a402f30c8a2ee409f8c6f393e95a63f8c952cc
- https://lists.apache.org/thread.html/r182e9cf6f3fb22b9be0cac4ff0685199741d2ab6e9
- https://lists.apache.org/thread.html/r191ceadb1b883357384981848dfa5235cb02a90070
- https://lists.apache.org/thread.html/r1aab47b48a757c70e40fc0bcb1fcf1a3951afa6a17
- https://lists.apache.org/thread.html/r1dfac8b6a7097bcb4979402bbb6e2f8c36d0d9001e
- https://lists.apache.org/thread.html/r1ffce2ed3017e9964f03ad2c539d69e49144fc8e9b
- https://lists.apache.org/thread.html/r20350031c60a77b45e0eded33e9b3e9cb0cbfc5e24
- https://lists.apache.org/thread.html/r22ac2aa053b7d9c6b75a49db78125c9316499668d0
FAQ
What is CVE-2017-18640?
CVE-2017-18640 is a vulnerability with a CVSS score of 7.5 (HIGH). The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
How severe is CVE-2017-18640?
CVE-2017-18640 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18640?
Check the references section above for vendor advisories and patch information. Affected products include: Snakeyaml Project Snakeyaml, Fedoraproject Fedora, Quarkus Quarkus, Oracle Peoplesoft Enterprise Pt Peopletools.