Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Stack Overflow in Snakeyaml
Vulnerability Description
Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
SnakeYAML 缓冲区错误漏洞
Vulnerability Description
SnakeYAML是一款基于Java的YAML解析器。 SnakeYAML 存在安全漏洞,该漏洞源于其解析攻击者提供的恶意YAML文件可能导致解析器因栈溢出而崩溃造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A