Skip to content

Commit

Permalink
CVE-2022-1471- SnakeYaml remote code execution by sending malicious Y…
Browse files Browse the repository at this point in the history
…AML content

Closes keycloak#25261
Signed-off-by: Douglas Palmer [email protected]
  • Loading branch information
douglaspalmer authored and mposolda committed Jan 24, 2024
1 parent 21bdea3 commit ee5593a
Showing 1 changed file with 12 additions and 0 deletions.
12 changes: 12 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,7 @@
<xmlsec.version>2.2.6</xmlsec.version>
<nashorn.version>15.4</nashorn.version>
<ua-parser.version>1.5.4</ua-parser.version>
<org.yaml.snakeyaml.version>2.0</org.yaml.snakeyaml.version>
<picketbox.version>5.0.3.Final</picketbox.version>
<xstream.version>1.4.20</xstream.version>
<org.snakeyaml.snakeyaml-engine.version>2.6</org.snakeyaml.snakeyaml-engine.version>
Expand Down Expand Up @@ -430,6 +431,17 @@
<groupId>com.github.ua-parser</groupId>
<artifactId>uap-java</artifactId>
<version>${ua-parser.version}</version>
<exclusions>
<exclusion>
<groupId>org.yaml</groupId>
<artifactId>snakeyaml</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.yaml</groupId>
<artifactId>snakeyaml</artifactId>
<version>${org.yaml.snakeyaml.version}</version>
</dependency>

<!--JAKARTA-->
Expand Down

0 comments on commit ee5593a

Please sign in to comment.