[MAVEN:GHSA-V54F-XCMP-43CR] Deserialization of Untrusted Data in Apache ShardingSphere

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.

Package Affected Version
pkg:maven/org.apache.shardingsphere/shardingsphere >= 4.0.0-RC3, <= 4.0.0
ID
MAVEN:GHSA-V54F-XCMP-43CR
Severity
high
URL
https://github.com/advisories/GHSA-v54f-xcmp-43cr
Published
2022-02-10T20:39:47
(2 years ago)
Modified
2023-02-01T05:05:38
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.shardingsphere/shardingsphere org.apache.shardingsphere shardingsphere >= 4.0.0-RC3 <= 4.0.0
Fixed pkg:maven/org.apache.shardingsphere/shardingsphere org.apache.shardingsphere shardingsphere = 4.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...