[jira] [Commented] (CASSANDRA-18083) snakeyaml-1.26.jar: CVE-2022-41854

2022-12-04 Thread Berenguer Blasi (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18083?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17643137#comment-17643137 ] Berenguer Blasi commented on CASSANDRA-18083: - I have been thinking instances where we

[jira] [Commented] (CASSANDRA-18083) snakeyaml-1.26.jar: CVE-2022-41854

2022-11-30 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18083?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17641422#comment-17641422 ] Brandon Williams commented on CASSANDRA-18083: -- 3.0 also has (for snakeyaml):

[jira] [Commented] (CASSANDRA-18083) snakeyaml-1.26.jar: CVE-2022-41854

2022-11-30 Thread Brandon Williams (Jira)
[ https://issues.apache.org/jira/browse/CASSANDRA-18083?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17641394#comment-17641394 ] Brandon Williams commented on CASSANDRA-18083: -- bq. Those using Snakeyaml to parse