[ 
https://issues.apache.org/jira/browse/TOMEE-4194?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17704589#comment-17704589
 ] 

RAJU THANNEERU commented on TOMEE-4194:
---------------------------------------

As per [https://nvd.nist.gov/vuln/detail/CVE-2022-1471,] this CVE is addressed 
in snakeyaml 2.0.

snakeyaml 2.0 version is available now in maven repo, see 
[https://mvnrepository.com/artifact/org.yaml/snakeyaml]

 

> Update snakeyaml version to 2.0 to mitigate CVE-2022-1471
> ---------------------------------------------------------
>
>                 Key: TOMEE-4194
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4194
>             Project: TomEE
>          Issue Type: Bug
>          Components: TomEE Core Server
>    Affects Versions: 8.0.14
>            Reporter: RAJU THANNEERU
>            Priority: Major
>
> Update snakeyaml version to 2.0 to mitigate CVE-2022-1471
> https://nvd.nist.gov/vuln/detail/CVE-2022-1471



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to