Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-1471

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.938
EPSS Ranking 99.9%
CVSS Severity
CVSS v3 Score 8.3
References
Products affected by CVE-2022-1471


Contact Us

Shodan ® - All rights reserved