HIGH 7.5 Maven
kaml has potential denial of service while parsing input with anchors and aliases
GHSA-c24f-2j3g-rg48 · CVE-2023-28118
Published · Modified
Description
Impact
Applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash.
Patches
Version 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases.
Workarounds
None.
References
Wikipedia has an explanation of this class of vulnerability: billion laughs attack
Acknowledgements
Thank you to @gdude2002 for reporting this issue.
References
- WEB https://github.com/charleskorn/kaml/security/advisories/GHSA-c24f-2j3g-rg48
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-28118
- WEB https://github.com/charleskorn/kaml/commit/5f82a2d7e00bfc307afca05d1dc4d7c50593531a
- PACKAGE https://github.com/charleskorn/kaml
- WEB https://github.com/charleskorn/kaml/releases/tag/0.53.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes