Uploaded image for project: 'Talend DI components'
  1. Talend DI components
  2. TDI-48471

Denial Of Service (DoS) in Talend/cloud-components (master)--snakeyaml 1.32

Apply templateInsert Lucidchart Diagram
    XMLWordPrintable

Details

    • GreenHopper Ranking:
      0|i2j1qz:
    • 9223372036854775807

    Description

      Denial Of Service (DoS) in Talend/cloud-components (master)

      Issue Details

      • Vulnerability: Denial Of Service (DoS)
      • Severity: Medium
      • Project: Talend/cloud-components
      • Branch: master
      • Scan Date: Unknown

      Issue Description

      snakeyaml is vulnerable to denial of service. The vulnerability exists because the `Composer` function of `Composer.java` does not properly restrict the nested depth limitation for collections, allowing an attacker to crash the application.

      View more details

      Attachments

        Activity

          People

            pteyssier pierre teyssier
            wwang Wei Wang
            Dmytro Grygorenko (Inactive), qiyan liu
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 4 hours
                4h