CVE-2022-1471 - org.yaml:snakeyaml, org.yaml:SnakeYAML in 2.15.3.Final #30339
-
Hello community, we are getting OWASP and AWS ECR findings with the latest quarkus version. I wasn't able to find any relevant information or announcements from quarkus side regarding this topic. We have YAML as a dependency in project only to be able to store our properties in application.yml file. Does anyone knows if this finding with SnakeYAML is false positive or if not then how to solve it? Thanks and regards, |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
@adisnuhan Please see #30124, Quarkus is not really impacted, but it will be closed once the next snakeyaml version with the hardening updates is released |
Beta Was this translation helpful? Give feedback.
@adisnuhan Please see #30124, Quarkus is not really impacted, but it will be closed once the next snakeyaml version with the hardening updates is released