-
Notifications
You must be signed in to change notification settings - Fork 172
Closed
Description
Hi, In /,there is a dependency org.yaml:snakeyaml:1.27 that calls the risk method.
The scope of this CVE affected version is [0,1.31)
After further analysis, in this project, the main Api called is org.yaml.snakeyaml.composer.Composer: composeNode(org.yaml.snakeyaml.nodes.Node)Lorg.yaml.snakeyaml.nodes.Node;
Risk method repair link : GitHub
CVE Bug Invocation Path--
Path Length : 5
com.hubspot.jinjava.lib.tag.RawTag: interpret(com.hubspot.jinjava.tree.TagNode,com.hubspot.jinjava.interpret.JinjavaInterpreter)Ljava.lang.String; /download/apache-maven-3.6.3/repository_mount/com/googlecode/java-ipv6/java-ipv6/0.17/java-ipv6-0.17.jar
org.yaml.snakeyaml.Yaml$1: next()Ljava.lang.Object; /download/apache-maven-3.6.3/repository_mount/ch/obermuhlner/big-math/2.0.0/big-math-2.0.0.jar
org.yaml.snakeyaml.constructor.BaseConstructor: getData()Ljava.lang.Object; /download/apache-maven-3.6.3/repository_mount/ch/obermuhlner/big-math/2.0.0/big-math-2.0.0.jar
org.yaml.snakeyaml.composer.Composer: getNode()Lorg.yaml.snakeyaml.nodes.Node; /download/apache-maven-3.6.3/repository_mount/ch/obermuhlner/big-math/2.0.0/big-math-2.0.0.jar
org.yaml.snakeyaml.composer.Composer: composeNode(org.yaml.snakeyaml.nodes.Node)Lorg.yaml.snakeyaml.nodes.Node;
Dependency tree--
[INFO] com.hubspot.jinjava:jinjava:jar:2.7.1-SNAPSHOT
[INFO] +- org.slf4j:slf4j-api:jar:1.7.25:compile
[INFO] +- com.google.guava:guava:jar:25.0-jre:compile
[INFO] | +- org.checkerframework:checker-compat-qual:jar:2.0.0:compile
[INFO] | +- com.google.errorprone:error_prone_annotations:jar:2.2.0:compile
[INFO] | +- com.google.j2objc:j2objc-annotations:jar:1.1:compile
[INFO] | \- org.codehaus.mojo:animal-sniffer-annotations:jar:1.14:compile
[INFO] +- org.javassist:javassist:jar:3.24.1-GA:compile
[INFO] +- org.jsoup:jsoup:jar:1.14.2:compile
[INFO] +- de.odysseus.juel:juel-api:jar:2.2.7:compile
[INFO] +- de.odysseus.juel:juel-impl:jar:2.2.7:compile
[INFO] +- com.google.re2j:re2j:jar:1.2:compile
[INFO] +- org.apache.commons:commons-lang3:jar:3.9:compile
[INFO] +- commons-net:commons-net:jar:3.9.0:compile
[INFO] +- com.googlecode.java-ipv6:java-ipv6:jar:0.17:compile
[INFO] +- com.google.code.findbugs:annotations:jar:3.0.1:compile
[INFO] +- com.fasterxml.jackson.core:jackson-annotations:jar:2.12.6:compile
[INFO] +- com.fasterxml.jackson.core:jackson-databind:jar:2.12.6:compile
[INFO] +- com.fasterxml.jackson.core:jackson-core:jar:2.12.6:compile
[INFO] +- com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:jar:2.12.6:compile
[INFO] | \- org.yaml:snakeyaml:jar:1.27:compile
[INFO] +- ch.obermuhlner:big-math:jar:2.0.0:compile
[INFO] +- ch.qos.logback:logback-core:jar:1.2.3:test
[INFO] +- ch.qos.logback:logback-classic:jar:1.2.3:test
[INFO] +- junit:junit:jar:4.12:test
[INFO] | \- org.hamcrest:hamcrest-core:jar:1.3:test
[INFO] +- org.assertj:assertj-core:jar:3.4.1:test
[INFO] \- org.mockito:mockito-core:jar:2.23.4:test
[INFO] +- net.bytebuddy:byte-buddy:jar:1.9.3:test
[INFO] +- net.bytebuddy:byte-buddy-agent:jar:1.9.3:test
[INFO] \- org.objenesis:objenesis:jar:2.6:test
Suggested solutions:
Update dependency version
Thank you very much.
Metadata
Metadata
Assignees
Labels
No labels