{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-04T12:25:24.152","vulnerabilities":[{"cve":{"id":"CVE-2022-1471","sourceIdentifier":"cve-coordination@google.com","published":"2022-12-01T11:15:10.553","lastModified":"2025-06-18T09:15:47.243","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond."},{"lang":"es","value":"La clase Constructor() de SnakeYaml no restringe los tipos de los que se pueden crear instancias durante la deserialización. La deserialización del contenido yaml proporcionado por un atacante puede conducir a la ejecución remota de código. Recomendamos utilizar SafeConsturctor de SnakeYaml al analizar contenido que no es de confianza para restringir la deserialización. Recomendamos actualizar a la versión 2.0 y posteriores."}],"metrics":{"cvssMetricV31":[{"source":"cve-coordination@google.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"cve-coordination@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:snakeyaml_project:snakeyaml:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"3598DC3A-DDD1-4A0B-ACDA-406B85A1EA1A"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","source":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2023/11/19/1","source":"cve-coordination@google.com"},{"url":"https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","source":"cve-coordination@google.com","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","source":"cve-coordination@google.com"},{"url":"https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","source":"cve-coordination@google.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mbechler/marshalsec","source":"cve-coordination@google.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","source":"cve-coordination@google.com"},{"url":"https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c","source":"cve-coordination@google.com"},{"url":"https://security.netapp.com/advisory/ntap-20230818-0015/","source":"cve-coordination@google.com"},{"url":"https://security.netapp.com/advisory/ntap-20240621-0006/","source":"cve-coordination@google.com"},{"url":"https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true","source":"cve-coordination@google.com","tags":["Exploit","Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2023/11/19/1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mbechler/marshalsec","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230818-0015/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240621-0006/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}