The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2019-12-12 03:15
Updated : 2024-11-21 03:20
NVD link : CVE-2017-18640
Mitre link : CVE-2017-18640
CVE.ORG link : CVE-2017-18640
JSON object : View
Products Affected
oracle
- peoplesoft_enterprise_pt_peopletools
quarkus
- quarkus
snakeyaml_project
- snakeyaml
fedoraproject
- fedora
CWE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')