CVE-2017-18640
12.12.2019, 03:15
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
| Vendor | Product | Version |
|---|---|---|
| snakeyaml_project | snakeyaml | 𝑥 < 1.26 |
| quarkus | quarkus | 𝑥 ≤ 1.3.4 |
| oracle | peoplesoft_enterprise_pt_peopletools | 8.56 |
| oracle | peoplesoft_enterprise_pt_peopletools | 8.57 |
| oracle | peoplesoft_enterprise_pt_peopletools | 8.58 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References