Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bumb version of snakeyaml to fix security issue in snakeyaml < 1.26 #11167

Merged
merged 2 commits into from
Sep 17, 2021
Merged

bumb version of snakeyaml to fix security issue in snakeyaml < 1.26 #11167

merged 2 commits into from
Sep 17, 2021

Conversation

philipplewe
Copy link
Contributor

@philipplewe philipplewe commented Sep 15, 2021

PR checklist

  • Read the contribution guidelines.
  • Ran the shell script under ./bin/ to update Petstore sample so that CIs can verify the change. (For instance, only need to run ./bin/{LANG}-petstore.sh and ./bin/security/{LANG}-petstore.sh if updating the {LANG} (e.g. php, ruby, python, etc) code generator or {LANG} client's mustache templates). Windows batch files can be found in .\bin\windows\.
  • Filed the PR against the correct branch: 3.0.0 branch for changes related to OpenAPI spec 3.0. Default: master.
  • Copied the technical committee to review the pull request if your PR is targeting a particular programming language.

Description of the PR

Version bump of snakeyaml to recent version in order to fix a security vulnerability in snakeyaml < 1.26.

Background: One of my clients uses Blackduck to scan security of their products.
Blackduck reported swagger-codegen-cli-2.4.21.jar to have transitive dependency to snakeyaml-1.24.

"SnakeYAML is vulnerable to a billion laughs attack. An attacker able to supply specially crafted input to the application could cause excessive memory consumption, resulting in a denial-of-service (DoS)."

SnakeYaml Issue: https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion

Fixed in https://bitbucket.org/asomov/snakeyaml/src/snakeyaml-1.26/
Fix Commit ID: : https://bitbucket.org/asomov/snakeyaml/commits/da11ddbd91c1f8392ea932b37fa48110fa54ed8c"

@frantuma frantuma merged commit cf38a24 into swagger-api:master Sep 17, 2021
@philipplewe philipplewe deleted the feature/update-snakeyaml-hotfix-based-v2.4.21 branch September 21, 2021 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants