{"id":"GHSA-vj49-j7rc-h54f","summary":"Esoteric YamlBeans XML Entity Expansion vulnerability","details":"An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and memory consumption, such as a Java Out-of-Memory exception.","aliases":["CVE-2023-24620"],"modified":"2023-11-09T05:32:59.175049Z","published":"2023-08-25T21:30:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-25T22:04:01Z","nvd_published_at":"2023-08-25T20:15:07Z","cwe_ids":["CWE-400","CWE-611"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24620"},{"type":"WEB","url":"https://contrastsecurity.com"},{"type":"WEB","url":"https://github.com/Contrast-Security-OSS/yamlbeans/blob/main/SECURITY.md"},{"type":"WEB","url":"https://github.com/EsotericSoftware"},{"type":"PACKAGE","url":"https://github.com/EsotericSoftware/yamlbeans"}],"affected":[{"package":{"name":"com.esotericsoftware.yamlbeans:yamlbeans","ecosystem":"Maven","purl":"pkg:maven/com.esotericsoftware.yamlbeans/yamlbeans"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.15"}]}],"versions":["1.06","1.08","1.09","1.11","1.12","1.13","1.14","1.15"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-vj49-j7rc-h54f/GHSA-vj49-j7rc-h54f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}