Known vulnerabilities in eap7-snakeyaml (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:eap7-snakeyaml_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 31
Public exploits: 11
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting eap7-snakeyaml (Red Hat package) eap7-snakeyaml (Red Hat package) is affected by 31 known vulnerabilities: 2 critical, 12 high, 13 medium, 4 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73219 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-1108
CWE-835 Medium
No
No
1.33.0-2.SP1_redhat_00001.1.el7eap, 1.33.0-2.SP1_redhat_00001.1.el8eap, 1.33.0-2.SP1_redhat_00001.1.el9eap 10.03.2023 SB2023031005
SB2023031008
SB2023031009
and 15 more
#VU72075 - Insecure Temporary File
CVE-2023-0482
CWE-377 Low
No
No
1.33.0-2.SP1_redhat_00001.1.el7eap, 1.33.0-2.SP1_redhat_00001.1.el8eap, 1.33.0-2.SP1_redhat_00001.1.el9eap 08.02.2023 SB2023020877
SB2023033003
SB2023033004
and 36 more
#VU71109 - Out-of-bounds write
CVE-2022-45693
CWE-787 Medium
No
No
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 11.01.2023 SB2023011159
SB2023011160
SB2023013112
and 45 more
#VU70530 - Deserialization of Untrusted Data
CVE-2022-45047
CWE-502 High
Available
No
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 28.12.2022 SB2022122828
SB2022122920
SB2023011148
and 49 more
#VU70443 - Exposure of sensitive information to an unauthorized actor
CVE-2022-46363
CWE-200 Low
No
No
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 20.12.2022 SB2022122009
SB2023011707
SB2023012719
and 22 more
#VU68832 - Resource exhaustion
CVE-2022-42004
CWE-400 Medium
No
No
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 31.10.2022 SB2022103116
SB2022103117
SB2022111404
and 122 more
#VU68635 - Deserialization of Untrusted Data
CVE-2022-42003
CWE-502 Medium
No
No
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 25.10.2022 SB2022102509
SB2022102510
SB2022103117
and 208 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Available
Exploited
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
1.33.0-1.SP1_redhat_00001.1.el7eap 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU61937 - Deserialization of Untrusted Data
CVE-2021-42392
CWE-502 Critical
Available
No
1.33.0-1.SP1_redhat_00001.1.el7eap 06.04.2022 SB2022040617
SB2022040619
SB2022042257
and 10 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU58178 - Files or Directories Accessible to External Parties
CVE-2021-3717
CWE-552 Low
No
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 16.11.2021 SB2021111608
SB2021111715
SB2022080830
and 3 more
#VU51511 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-13936
CWE-94 High
No
No
1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7 16.03.2021 SB2021031618
SB2021072614
SB2022011911
and 45 more
#VU26494 - Deserialization of Untrusted Data
CVE-2020-10673
CWE-502 High
Available
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 01.04.2020 SB2020030909
SB2020073033
SB2022060909
and 17 more
#VU26493 - Deserialization of Untrusted Data
CVE-2020-10672
CWE-502 High
No
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 01.04.2020 SB2020030909
SB2020073033
SB2022060909
and 16 more
#VU25832 - Deserialization of Untrusted Data
CVE-2020-9548
CWE-502 High
Available
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 09.03.2020 SB2020030909
SB2020073033
SB2022060909
and 14 more
#VU25831 - Deserialization of Untrusted Data
CVE-2020-9547
CWE-502 High
Available
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 09.03.2020 SB2020030909
SB2020073033
SB2022060909
and 13 more
#VU25830 - Deserialization of Untrusted Data
CVE-2020-9546
CWE-502 High
No
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 09.03.2020 SB2020030909
SB2020071523
SB2020071620
and 31 more
#VU25469 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-8840
CWE-94 Medium
Available
No
1.33.0-1.SP1_redhat_00001.1.ep7.el7 19.02.2020 SB2020021921
SB2020022615
SB2020061106
and 18 more


Showing elements 1 - 20 out of 31