{"id":"GHSA-39vw-qp34-rmwf","aliases":["RUSTSEC-2018-0005"],"url":"https://o3.security/vulnerability/GHSA-39vw-qp34-rmwf","summary":"Uncontrolled recursion leads to abort in deserialization","details":"Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.\n","published":"2021-08-25T21:00:18Z","modified":"2023-11-08T04:14:33.650192Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"serde_yaml","fixedVersion":"0.8.4"}],"fix":{"url":"https://github.com/dtolnay/serde-yaml/pull/105","label":"dtolnay/serde-yaml#105"},"references":[{"type":"WEB","url":"https://github.com/dtolnay/serde-yaml/pull/105"},{"type":"WEB","url":"https://github.com/dtolnay/serde-yaml/commit/b93aff6e904cffbbfd1f421b82f6dcc5ca19a4fd"},{"type":"PACKAGE","url":"https://github.com/dtolnay/serde-yaml"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2018-0005.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:14:33.650192Z"}}