Netcentric / accesscontroltool

Rights and roles management for AEM made easy
Eclipse Public License 1.0
147 stars 92 forks source link

Update SnakeYAML to prevent multiple vulnerabilities #642

Closed kwin closed 1 year ago

kwin commented 1 year ago

The following vulnerabilities are fixed in 1.32:

  1. https://nvd.nist.gov/vuln/detail/CVE-2022-38752
  2. https://nvd.nist.gov/vuln/detail/CVE-2022-38751
  3. https://nvd.nist.gov/vuln/detail/CVE-2022-38750
  4. https://nvd.nist.gov/vuln/detail/CVE-2022-25857
  5. https://nvd.nist.gov/vuln/detail/CVE-2022-38749
kwin commented 1 year ago

There is still the unclosed https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081 (CVE-2022-38752. Probably needs to be marked as false-positive... Compare also with https://bitbucket.org/snakeyaml/snakeyaml/wiki/CVE%20&%20NIST

kwin commented 1 year ago

All known vulnerabilities are fixed with SnakeYAML 1.32 which has been included now.