Skip to content
This repository has been archived by the owner on Feb 12, 2022. It is now read-only.

Vulnerable version snakeyaml #692

Open
kuramsai opened this issue Apr 17, 2020 · 1 comment
Open

Vulnerable version snakeyaml #692

kuramsai opened this issue Apr 17, 2020 · 1 comment

Comments

@kuramsai
Copy link

RAML-parser.0.8.37 uses snakeyaml(1.23) which has known vulnerabilities and it is recommended to update it to 1.26 or later.

Upgrading to RAML-Parser 1.x is not possible as the format has changed in 1.x

So request you to update snakeyaml to 1.26 in 0.8.x version.

Referenced for security issue:
https://snyk.io/vuln/SNYK-JAVA-ORGYAML-537645
https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion

@jstoiko
Copy link
Contributor

jstoiko commented Jun 30, 2020

Please note that this parser is now deprecated and is about to be archived, please use webapi-parser moving forward.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants