sparkutils / quality

A Quality Spark DQ Library
https://sparkutils.github.io/quality/
Apache License 2.0
4 stars 2 forks source link

snake yaml 2.0 - cve-2022-1471 #55

Closed chris-twiner closed 8 months ago

chris-twiner commented 8 months ago

https://www.veracode.com/blog/research/resolving-cve-2022-1471-snakeyaml-20-release-0

restrict to java.lang types and fix UTF8String to use java.lang.String type.

chris-twiner commented 8 months ago

verified on 14.0 dbr