Skip to content
This repository was archived by the owner on Feb 12, 2022. It is now read-only.
This repository was archived by the owner on Feb 12, 2022. It is now read-only.

Vulnerable version snakeyaml #692

@kuramsai

Description

@kuramsai

RAML-parser.0.8.37 uses snakeyaml(1.23) which has known vulnerabilities and it is recommended to update it to 1.26 or later.

Upgrading to RAML-Parser 1.x is not possible as the format has changed in 1.x

So request you to update snakeyaml to 1.26 in 0.8.x version.

Referenced for security issue:
https://snyk.io/vuln/SNYK-JAVA-ORGYAML-537645
https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions