Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update SnakeYAML to 1.29 (was 1.25: vulnerable to "billion laughs")
Kudos to Noriko Totsuka of @JPCERTCC (and also the author of the vulnerability report, Taichi Kotake of Akatsuki Inc.) for reporting the "billion laughs" vulnerability in SnakeYAML 1.25 (that the JVM build of Kaitai Struct compiler has been using so far) to us. Note: I am deliberately not updating to the latest version 1.30 because it contains a suspicious regular expression, see https://bitbucket.org/snakeyaml/snakeyaml/issues/537/potentially-problematic-regular-expression. At least until someone proves it's safe under all circumstances, or fixes it to a 100% harmless version as I suggest, I won't be using any newer version than 1.29 unless I know it's safe.
- Loading branch information