Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade org.yaml.snakeyaml to fix CVE-2022-25857 #33355

Closed
steinsag opened this issue Nov 25, 2022 · 4 comments
Closed

Upgrade org.yaml.snakeyaml to fix CVE-2022-25857 #33355

steinsag opened this issue Nov 25, 2022 · 4 comments
Labels
status: duplicate A duplicate of another issue

Comments

@steinsag
Copy link

Neither in Spring Boot 2.7.6 nor in 3.0.0, org.yaml.snakeyaml was upgraded to latest release 1.32 or 1.33 fixing

CVE-2022-25857

As this is a managed dependency, is there maybe something wrong with automated upgrade in case of snakeyaml?

We are running several services in production with Spring Boot 2.7.5 and snakeyaml 1.32 without any problems.

PS: There is still another open unfixed security bug in snakeyaml: CVE-2022-41854

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Nov 25, 2022
@bclozel
Copy link
Member

bclozel commented Nov 25, 2022

Nothing went wrong, this is due to our upgrade policy.
Duplicates #32221

@bclozel bclozel closed this as not planned Won't fix, can't repro, duplicate, stale Nov 25, 2022
@bclozel bclozel added status: duplicate A duplicate of another issue and removed status: waiting-for-triage An issue we've not yet triaged labels Nov 25, 2022
@steinsag
Copy link
Author

Ok, understood for Spring Boot 2.x, but why hasn't it be upgraded for Spring Boot 3.x, which would allow breaking changes?

@bclozel
Copy link
Member

bclozel commented Nov 25, 2022

I don't understand, Spring Boot 3.0.0 depends on SnakeYaml 1.33. Which version should we upgrade to?

@steinsag
Copy link
Author

Eiks, too many repos on my side, mixed things up :-/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: duplicate A duplicate of another issue
Projects
None yet
Development

No branches or pull requests

3 participants