SnakeYAML是一款基于Java的YAML解析器。 SnakeYaml存在代码问题漏洞,该漏洞源于不限制在反序列化期间可以实例化的类型。攻击者利用该漏洞可以远程执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Code for veracode blog | https://github.com/1fabunicorn/SnakeYAML-CVE-2022-1471-POC | POC Details |
| 2 | SnakeYAML-CVE-2022-1471-POC | https://github.com/falconkei/snakeyaml_cve_poc | POC Details |
| 3 | SnakeYAML CVE-2022-1471 exploit payload for demo | https://github.com/seal-sec-demo-2/yaml-payload | POC Details |
No public POC found.
Login to generate AI POCNo comments yet