io.fabric8:fabric8-maven-plugin-core@4.4.0 vulnerabilities

  • latest version

    4.4.2

  • first published

    5 years ago

  • latest version published

    2 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the io.fabric8:fabric8-maven-plugin-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Deserialization of Untrusted Data

    io.fabric8:fabric8-maven-plugin-core is an one-stop-shop for building and deploying Java applications for Docker, Kubernetes and OpenShift.

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in via YamlUtil.java could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    How to fix Deserialization of Untrusted Data?

    There is no fixed version for io.fabric8:fabric8-maven-plugin-core.

    [4.2.0,)