Skip to content

Change yaml parser to org.snakeyaml:snakeyaml-engine #79

Description

@NAJ10

The existing snakeyaml library is listed as vulnerable to security vulnerabilities because it allows create of arbitrary java objects which could lead to remote code execution. org.snakeyaml:snakeyaml-engine seems to be a follow on from the existing snakeyaml library from the same developers but is able to parse YAML 1.2. Please could you consider using snakeyaml-engine to help developers working in organisations where automated security scanning for vulnerable dependencies causes friction between in house security teams and ordinary developers who happen to pull in uap-java as a dependency.

Activity

  1. NAJ10 commented on Feb 23, 2023

    @NAJ10
    Author

    This will also address #68

  2. bpossolo commented on Feb 26, 2023

    @bpossolo
    Contributor

    At first I was hoping the snakeyaml maintainers would address the issue in their library but I read through their issue/conversation and, apparently, it's very controversial...

    I'll check out snakeyaml-engine and see how complicated it is to swap over.

  3. thomasdarimont commented on Feb 28, 2023

    @thomasdarimont

    How about simply removing the dependency to snakeyaml?

    The regex format file regexes.yaml is quite simple and could be parsed by a small handwritten parser that just turns the yaml into a ``Map<String,List<Map<String,String>>>`

  4. bpossolo commented on Mar 5, 2023

    @bpossolo
    Contributor

    I'd prefer to avoid writing a custom yaml parser

  5. aminadinari19 commented on Mar 8, 2023

    @aminadinari19

    Hi! There is a new version of snakeyaml (2.0) which seems to be free of vulnerabilities. Do you plan to upgrade to that?

  6. jmini commented on Apr 6, 2023

    @jmini

    I have opened a PR to update to version 2.0 of the regular snakeyaml: #82

    I agree with the discussion here, snakeyaml-engine might be a good fit for this library:
    https://bitbucket.org/snakeyaml/snakeyaml-engine/wiki/Home

  7. jmini commented on Apr 7, 2023

    @jmini

    I think it is even better to remove the need to have any YAML parsing at runtime.

    So I have opened a PR for that: #83

  8. bpossolo commented on Nov 28, 2023

    @bpossolo
    Contributor

    I'm pleased to announce version 1.6.1 has been released to Maven Central and the security vulnerability has been addressed.

    see here for what's changed
    https://github.com/ua-parser/uap-java/releases/tag/v1.6.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions