CVE编号
CVE-2017-18640利用情况
暂无补丁情况
官方补丁披露时间
2019-12-12漏洞描述
SnakeYAML 1.18中的Alias功能允许在加载操作期间扩展实体,这是CVE-2003-1564的相关问题。解决建议
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:https://github.com/asomov/snakeyaml
参考链接 |
|
---|---|
https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-pre... | |
https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attack | |
https://lists.apache.org/thread.html/r1058e7646988394de6a3fd0857ea9b1ee0de14d... | |
https://lists.apache.org/thread.html/r154090b871cf96d985b90864442d84eb027c72c... | |
https://lists.apache.org/thread.html/r16ae4e529401b75a1f5aa462b272b31bf2a1082... | |
https://lists.apache.org/thread.html/r1703a402f30c8a2ee409f8c6f393e95a63f8c95... | |
https://lists.apache.org/thread.html/r182e9cf6f3fb22b9be0cac4ff0685199741d2ab... | |
https://lists.apache.org/thread.html/r191ceadb1b883357384981848dfa5235cb02a90... | |
https://lists.apache.org/thread.html/r1aab47b48a757c70e40fc0bcb1fcf1a3951afa6... | |
https://lists.apache.org/thread.html/r1dfac8b6a7097bcb4979402bbb6e2f8c36d0d90... | |
https://lists.apache.org/thread.html/r1ffce2ed3017e9964f03ad2c539d69e49144fc8... | |
https://lists.apache.org/thread.html/r20350031c60a77b45e0eded33e9b3e9cb0cbfc5... | |
https://lists.apache.org/thread.html/r22ac2aa053b7d9c6b75a49db78125c931649966... | |
https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747... | |
https://lists.apache.org/thread.html/r28c9009a48d52cf448f8b02cd823da0f8601d2d... | |
https://lists.apache.org/thread.html/r2a5b84fdf59042dc398497e914b5bb1aed77328... | |
https://lists.apache.org/thread.html/r2b05744c0c2867daa5d1a96832965b7d6220328... | |
https://lists.apache.org/thread.html/r2db207a2431a5e9e95e899858ab1f5eabd9bcc7... | |
https://lists.apache.org/thread.html/r436988d2cfe8a770ae361c82b181c5b2bf48a24... | |
https://lists.apache.org/thread.html/r465d2553a31265b042cf5457ef649b71e0722ab... | |
https://lists.apache.org/thread.html/r4c682fb8cf69dd14162439656a6ebdf42ea6ad0... | |
https://lists.apache.org/thread.html/r4d7f37da1bc2df90a5a0f56eb7629b5ea131bfe... | |
https://lists.apache.org/thread.html/r5510f0125ba409fc1cabd098ab8b457741e5fa3... | |
https://lists.apache.org/thread.html/r55d807f31e64a080c54455897c20b1667ec792e... | |
https://lists.apache.org/thread.html/r56805265475919252ba7fc10123f15b91097f30... | |
https://lists.apache.org/thread.html/r643ba53f002ae59068f9352fe1d82e1b6f37538... | |
https://lists.apache.org/thread.html/r666f29a7d0e1f98fa1425ca01efcfa86e6e3856... | |
https://lists.apache.org/thread.html/r6c91e52b3cc9f4e64afe0f34f20507143fd1f75... | |
https://lists.apache.org/thread.html/r6d54c2da792c74cc14b9b7665ea89e144c9e238... | |
https://lists.apache.org/thread.html/r72a3588d62b2de1361dc9648f5d355385735e47... | |
https://lists.apache.org/thread.html/r7ce3de03facf7e7f3e24fc25d26d555818519da... | |
https://lists.apache.org/thread.html/r8464b6ec951aace8c807bac9ea526d4f9e3116a... | |
https://lists.apache.org/thread.html/r8b57c57cffa01e418868a3c7535b987635ff1fb... | |
https://lists.apache.org/thread.html/r900e020760c89f082df1c6e0d46320eba721e4e... | |
https://lists.apache.org/thread.html/raebd2019b3da8c2f90f31e8b203b45353f78770... | |
https://lists.apache.org/thread.html/rb0e033d5ec8233360203431ad96580cf2ec56f4... | |
https://lists.apache.org/thread.html/rb34d8d3269ad47a1400f5a1a2d8310e13a80b65... | |
https://lists.apache.org/thread.html/rb5c33d0069c927fae16084f0605895b98d231d7... | |
https://lists.apache.org/thread.html/rb7b28ac741e32dd5edb2c22485d635275bead72... | |
https://lists.apache.org/thread.html/rbaa1f513d903c89a08267c91d86811fa5bcc82e... | |
https://lists.apache.org/thread.html/rc3211c71f7e0973a1825d1988a3921288c06cd9... | |
https://lists.apache.org/thread.html/rcb2a7037366c58bac6aec6ce3df843a11ef97ae... | |
https://lists.apache.org/thread.html/rcb4b61dbe2ed1c7a88781a9aff5a9e7342cc7ed... | |
https://lists.apache.org/thread.html/rce5c93bba6e815fb62ad38e28ca1943b3019af1... | |
https://lists.apache.org/thread.html/rd582c64f66c354240290072f340505f5d026ca9... | |
https://lists.apache.org/thread.html/rdd34c0479587e32a656d976649409487d51ca0d... | |
https://lists.apache.org/thread.html/re791a854001ec1f79cd4f47328b270e7a1d9d70... | |
https://lists.apache.org/thread.html/re851bbfbedd47c690b6e01942acb98ee08bd00d... | |
https://lists.apache.org/thread.html/reb1751562ee5146d3aca654a2df76a2c13d8036... | |
https://lists.apache.org/thread.html/recfe569f4f260328b0036f1c82b2956e864d519... | |
https://lists.apache.org/thread.html/rf95bebee6dfcc55067cebe8482bd31e6f481d9f... | |
https://lists.apache.org/thread.html/rfe0aab6c3bebbd9cbfdedb65ff3fdf420714bcb... | |
https://lists.fedoraproject.org/archives/list/[email protected]... | |
https://lists.fedoraproject.org/archives/list/[email protected]... | |
https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.25/usages | |
https://www.oracle.com/security-alerts/cpuApr2021.html |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | snakeyaml_project | snakeyaml | * |
Up to (excluding) 1.26 |
|||||
运行在以下环境 | |||||||||
系统 | centos_8 | snakeyaml | * |
Up to (excluding) 0.12.0-6.el8 |
|||||
运行在以下环境 | |||||||||
系统 | debian_10 | snakeyaml | * |
Up to (excluding) 1.23-1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | snakeyaml | * |
Up to (excluding) 1.17-1 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_31 | snakeyaml | * |
Up to (excluding) 1.26-1.fc31 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_32 | snakeyaml | * |
Up to (excluding) 1.26-1.fc32 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.2 | snakeyaml | * |
Up to (excluding) 1.28-lp152.2.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.3 | snakeyaml | * |
Up to (excluding) 1.28-3.5.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_8 | snakeyaml | * |
Up to (excluding) 0.12.0-6.el8 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_8 | snakeyaml | * |
Up to (excluding) 0.12.0-6.el8 |
|||||
- 攻击路径 远程
- 攻击复杂度 复杂
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 100
还没有评论,来说两句吧...