CRITICAL · 9.8

CVE-2022-31691

Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39...

Vulnerability Description

Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
VmwareBosh Editor>= 1.0.0, < 1.40.0
VmwareCloudfoundry Manifest Yml Support>= 1.0.0, < 1.40.0
VmwareConcourse Ci Pipeline Editor>= 1.0.0, < 1.40.0
VmwareSpring Boot Tools>= 1.0.0, < 1.40.0
VmwareSpring Tools>= 4.0.0, < 4.16.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-31691?

CVE-2022-31691 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39...

How severe is CVE-2022-31691?

CVE-2022-31691 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-31691?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Bosh Editor, Vmware Cloudfoundry Manifest Yml Support, Vmware Concourse Ci Pipeline Editor, Vmware Spring Boot Tools, Vmware Spring Tools.