CVE-2017-18640

Description

The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.166

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-18640 are fixed in Snake Yaml 1.26Windows
Multiple Vulnerabilities are affected in IBM Aspera Shares 1.10.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.8Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.4Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.5.2Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.8Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.2Windows
(RHSA-2020:4807) prometheus-jmx-exporter security update prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpmLinux
Vulnerabilities CVE-2017-18640 are fixed in Snake Yaml for Linux 1.26Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234