CVE-2022-31691
CRITICALVmware Bosh Editor < 1.40.0 - Code Injection
Title source: ruleDescription
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.1361
EPSS Percentile
94.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (5)
vmware/bosh_editor
1.0.0 - 1.40.0
vmware/cloudfoundry_manifest_yml_support
1.0.0 - 1.40.0
vmware/concourse_ci_pipeline_editor
1.0.0 - 1.40.0
vmware/spring_boot_tools
1.0.0 - 1.40.0
vmware/spring_tools
4.0.0 - 4.16.1
Published
Nov 04, 2022
Tracked Since
Feb 18, 2026