Skip to main content
Vulnerability Intelligence
Platform
Solutions
Customers
Resources
Company
Login
Get Demo
Vulnerability Intelligence
SUSE-SU-2021:1978-1
SUSE-SU-2021:1978-1
UNKNOWN
Security update for snakeyaml
Published Jun 15, 2021
Modified 4 years ago
Fix available
Details
This update for snakeyaml fixes the following issues:
Upgrade to 1.28
CVE-2017-18640: The Alias feature allows entity expansion during a load operation (bsc#1159488, bsc#1186088)
Affected Packages
snakeyaml
SUSE Manager Server Module 4.0
Fixed in:
1.28-12.3.1
References
REPORT
https://bugzilla.suse.com/1159488
REPORT
https://bugzilla.suse.com/1186088
WEB
https://www.suse.com/security/cve/CVE-2017-18640
ADVISORY
https://www.suse.com/support/update/announcement/2021/suse-su-20211978-1/
Upstream
CVE-2017-18640
Related
CVE-2017-18640
Ecosystems
SUSE Manager Server Module 4.0
Timeline
Published
Jun 15, 2021
Modified
Jun 15, 2021
SUSE-SU-2021:1978-1 | Mondoo Vulnerability Intelligence