Panic!! At the YAML
ID: 90b103c2-c031-5447-b15c-ec74eff041dd
STIX ID: report--90b103c2-c031-5447-b15c-ec74eff041dd
Feed Name: GreyNoise Labs
Threat Score
This write-up analyzes CVE-2022-1471 in SnakeYAML — an insecure-by-default YAML deserialization issue — and demonstrates a working proof-of-concept that uses YAML tags and Java URLClassLoader/ScriptEngineFactory gadgetry to fetch a malicious .class file and achieve remote code execution; it explains payload construction, serving the gadget, and the importance of the SnakeYAML 2.0 remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
