logo

Panic!! At the YAML

ID: 90b103c2-c031-5447-b15c-ec74eff041dd

STIX ID: report--90b103c2-c031-5447-b15c-ec74eff041dd

Feed Name: GreyNoise Labs

Threat Score
70/100

Date Published: 2024-01-03

Date Updated: 2026-04-27

Author: Ron Bowes

...
...

This write-up analyzes CVE-2022-1471 in SnakeYAML — an insecure-by-default YAML deserialization issue — and demonstrates a working proof-of-concept that uses YAML tags and Java URLClassLoader/ScriptEngineFactory gadgetry to fetch a malicious .class file and achieve remote code execution; it explains payload construction, serving the gadget, and the importance of the SnakeYAML 2.0 remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.