Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker.
Spring Tools 4 for Eclipse, Spring Tool Suite:
VSCode Extension, Spring Boot Tools:
VSCode Extension, Concourse CI Pipeline Editor:
VSCode Extension, Bosh Editor:
VSCode Extension, Cloudfoundry Manifest YML Support:
Users of affected versions of Spring Tools 4 for Eclipse should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 4.16.x | 4.16.1 | OSS |
Users of affected versions of a VSCode Extension should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 1.39.x | 1.40.0 | OSS |
This issue was identified and responsibly reported by Zewei Zhang from NSFOCUS TIANJI Lab.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy