Project

General

Profile

Actions

Bug #22983

closed

Snake-yaml dependency in zio-json is subjected to CVE

Added by François ARMAND 10 months ago. Updated 10 months ago.

Status:
Released
Priority:
N/A
Category:
Architecture - Code maintenance
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

zio-json-yaml comes with snakeyaml 1.33, which is subjected to cve-2022-1471 (https://www.veracode.com/blog/research/resolving-cve-2022-1471-snakeyaml-20-release-0)

We can use version 2.0 to correct the problem, what we tried to tell maven to do, but failed to.

Actions #1

Updated by François ARMAND 10 months ago

  • Status changed from New to In progress
  • Assignee set to François ARMAND
Actions #2

Updated by François ARMAND 10 months ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from François ARMAND to Alexis Mousset
  • Pull Request set to https://github.com/Normation/rudder/pull/4862
Actions #3

Updated by Anonymous 10 months ago

  • Status changed from Pending technical review to Pending release
Actions #4

Updated by Vincent MEMBRÉ 10 months ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 8.0.0~alpha1 which was released today.

Actions

Also available in: Atom PDF