Vulnerability Details CVE-2021-4235
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.5%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2021-4235
-
cpe:2.3:a:yaml_project:yaml:2.0.0
-
cpe:2.3:a:yaml_project:yaml:2.1.0
-
cpe:2.3:a:yaml_project:yaml:2.1.1
-
cpe:2.3:a:yaml_project:yaml:2.2.0
-
cpe:2.3:a:yaml_project:yaml:2.2.1
-
cpe:2.3:a:yaml_project:yaml:2.2.2