io.fabric8:fabric8-maven-plugin-core@4.4.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the io.fabric8:fabric8-maven-plugin-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Deserialization of Untrusted Data

io.fabric8:fabric8-maven-plugin-core is an one-stop-shop for building and deploying Java applications for Docker, Kubernetes and OpenShift.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in via YamlUtil.java could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

How to fix Deserialization of Untrusted Data?

There is no fixed version for io.fabric8:fabric8-maven-plugin-core.

[4.2.0,)