Skip to content

CVE-2022-1471 ? -> Not Applicable to jackson-dataformat-yaml #361

@jpcmonster

Description

@jpcmonster

Hi - are you able to comment on the usage of snakeyaml regarding CVE-2022-1471?
Is the team able to make a statement like this one?
spring-projects/spring-boot#33457 (comment)
Thanks!

|    |    |         +--- com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.14.0
|    |    |         |    +--- com.fasterxml.jackson.core:jackson-databind:2.14.0 (*)
|    |    |         |    +--- org.yaml:snakeyaml:1.33 -> 1.32
|    |    |         |    +--- com.fasterxml.jackson.core:jackson-core:2.14.0 (*)
|    |    |         |    \--- com.fasterxml.jackson:jackson-bom:2.14.0 (*)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions