False positive reported on SnakeYAML CVE-2022-1471
还没有人认领这个 Issue。
评估
调研方向
该 payload 没有指出任何仓库文件或测试。首先定位此仓库中表示依赖 org.yaml:snakeyaml 或漏洞数据的位置,然后重现针对版本 2.6 的 Xray 扫描。当 SnakeYAML 2.0 及更高版本不再报告 CVE-2022-1471 时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Describe the bug
Xray reports CVE-2022-1471 against org.yaml:snakeyaml 2.6. This CVE only affects SnakeYAML versions < 2.0 where the unsafe Constructor() class was the default. In 2.0+, SafeConstructor is the default and the vulnerability does not apply.
To Reproduce
Xray scan a software containing org.yaml:snakeyaml 2.6 and see CVE-2022-1471 reported. This CVE impacts SnakeYAML < 2.0 only. Version 2.6 is well above the fix threshold.
Expected behavior
CVE-2022-1471 should not be reported for SnakeYAML >= 2.0, as the vulnerability was resolved by making SafeConstructor the default in that version.
Versions
- Package: org.yaml:snakeyaml:2.6
- Vulnerable range per NVD: < 2.0
- Fix version: 2.0
Additional context
NVD advisory: https://github.com/advisories/GHSA-mjmj-j48q-9wg2
- 主要语言
- Java
- 星标
- 331
- 派生
- 164
- 平均合并
- 20 小时 9 分钟
- 30 天内合并 PR
- 1
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
jfrog/artifactory-client-java 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 65/100
jfrog/artifactory-client-java#450 · 2 条评论 ·
-
question
难度 2/5 1-3 小时 新手友好度 62/100
jfrog/artifactory-client-java#375 ·
-
难度 4/5 3-5 天 新手友好度 35/100
jfrog/artifactory-client-java#448 ·
-
难度 3/5 1-2 天 新手友好度 45/100
jfrog/artifactory-client-java#447 ·
-
难度 4/5 3-5 天 新手友好度 35/100
jfrog/artifactory-client-java#445 ·
查看 jfrog/artifactory-client-java 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
refinedmods/refinedstorage2#1414 · 1 条评论 ·
-
bug
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 2/5 1-3 小时 新手友好度 73/100
google/differential-privacy#489 ·
-
难度 1/5 1 小时以内 新手友好度 78/100
维护者通常 1 天内回复
-
link-check link-check:manual
难度 2/5 1-3 小时 新手友好度 85/100