Security Advisory

CVE-2023-24620

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-08-25 00:00:00
Last updated 2024-10-02 18:08:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and memory consumption, such as a Java Out-of-Memory exception.