Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@priyawadhwa
Copy link
Member

This is a High CVE, mapping to CVE-2022-1471.

The CVE is a RCE bug in snakeyaml, which is a plugin Jenkins pulls in. Based on this comment it looks like Jenkins has already verified that the vulnerable code is not present in the snakeyaml plugin. That PR would also pull in the CVE fix, but it hasn't been merged yet since it would create breaking changes.

There is no vulnerability in snakeyaml - it works as expected - the vulnerability is in any libraries that use it insecurely with untrusted data. The Jenkins plugin ecosystem has been checked for this usage.

@rawlingsj rawlingsj added this pull request to the merge queue Jul 25, 2023
Merged via the queue into wolfi-dev:main with commit c6a3a36 Jul 25, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants