{"id":"SUSE-SU-2024:2568-1","summary":"Security update for mockito, snakeyaml, testng","details":"This update for mockito, snakeyaml, testng fixes the following issues:\n\nmockito was updated to version 5.11.0:\n\n- Added bundle manifest to the mockito-core artifact\n- Mockito 5 is making core changes to ensure compatibility with future JDK versions.\n- Switch the Default MockMaker to mockito-inline (not applicable to mockito-android)\n\n  * Mockito 2.7.6 introduced the mockito-inline mockmaker based on the 'inline bytecode' principle, offering\n    compatibility advantages over the subclass mockmaker\n  * This change avoids JDK restrictions, such as violating module boundaries and leaking subclass creation\n\n- Legitimate use cases for the subclass mockmaker:\n\n  * Scenarios where the inline mockmaker does not function, such as on Graal VM's native image\n  * If avoiding mocking final classes, the subclass mockmaker remains a viable option, although issues may arise on\n    JDK 17+\n  * Mockito aims to support both mockmakers, allowing users to choose based on their requirements.\n\n- Update the Minimum Supported Java Version to 11\n\n  * Mockito 5 raised the minimum supported Java version to 11\n  * Community member @reta contributed to this change.\n  * Users still on JDK 8 can continue using Mockito 4, with minimal API differences between versions\n\n- New type() Method on ArgumentMatcher\n\n  * The ArgumentMatcher interface now includes a new type() method to support varargs methods, addressing previous\n    limitations\n  * Users can now differentiate between matching calls with any exact number of arguments or match any number of\n    arguments\n  * Mockito 5 provides a default implementation of the new method, ensuring backward compatibility.\n  * No obligation for users to implement the new method; Mockito 5 considers Void.type by default for varargs handling\n  * ArgumentCaptor is now fully type-aware, enabling capturing specific subclasses on a generic method.\n\n- byte-buddy does not bundle asm, but uses objectweb-asm as external library\n\nsnake-yaml was updated to version 2.2:\n\n- Changes of version 2.2:\n\n  * Define default scalar style as PLAIN (for polyglot Maven)\n  * Add missing 'exports org.yaml.snakeyaml.inspector' to module-info.java\n\n- Changes of version 2.1:\n\n  * Heavy Allocation in Emitter.analyzeScalar(String) due to Regex Overhead\n  * Use identity in toString() for sequences to avoid OutOfMemoryError\n  * NumberFormatException from SnakeYAML due to int overflow for corrupt YAML version\n  * Document size limit should be applied to single document notthe whole input stream\n  * Detect invalid Unicode code point (thanks to Tatu Saloranta)\n  * Remove Trusted*Inspector classes from main sources tree\n\n- Changes of version 2.0:\n\n  * Rollback to Java 7 target\n  * Add module-info.java\n  * Migrate to Java 8\n  * Remove many deprecated constructors\n  * Remove long deprecated methods in FlowStyle\n  * Do not allow global tags by default\n  * Yaml.LoadAs() signature to support Class\u003c? super T\u003e type instead of Class\u003cT\u003e\n  * CustomClassLoaderConstructor takes LoaderOptions\n  * Check input parameters for non-null values\n\ntestng was updated to version 7.10.1:\n\n- Security issues fixed:\n\n  * CVE-2022-4065: Fixed Zip Slip Vulnerability (bsc#1205628)\n\n- Changes of version 7.10.1:\n\n  * Fixed maven build with junit5\n\n- Changes of version 7.10.0:\n\n  * Minor discrepancy fixes\n  * Deleting TestNG eclipse plugin specific classes\n  * Remove deprecated JUnit related support in TestNG\n  * Handle exceptions in emailable Reporter\n  * Added wrapperbot and update workflow order\n  * Support ITestNGFactory customisation\n  * Streamlined data provider listener invocation\n  * Streamlined Guice Module creation in concurrency.\n  * Copy test result attributes when unexpected failures\n  * chore: use explicit dependency versions instead of refreshVersions\n  * Removed Ant\n  * Support ordering of listeners\n  * Added errorprone\n  * Allow custom thread pool executors to be wired in.\n  * Allow data providers to be non cacheable\n  * Use Locks instead of synchronised keyword\n  * Document pgp artifact signing keys\n  * Added Unique Id for all test class instances\n  * Added issue management workflows\n  * Map object to configurations\n  * Allow listeners to be disabled at runtime\n  * Streamlined Data Provider execution\n  * Honour inheritance when parsing listener factories\n  * Tweaks around accessing SuiteResult\n  * Streamlined random generation\n  * Streamlined dependencies for configurations\n\n- Changes of version 7.9.0:\n\n  * Fixed maps containing nulls can be incorrectly considered equal\n  * Test Results as artifacts for failed runs\n  * Fixed data races\n  * Dont honour params specified in suite-file tag\n  * Decouple SuiteRunner and TestRunner\n  * Disable Native DI for BeforeSuite methods\n  * Streamlined running Parallel Dataproviders+retries\n  * Removed extra whitespace in log for Configuration.createMethods()\n  * Added the link for TestNG Documentation's GitHub Repo in README.md\n  * FirstTimeOnlyConfig methods + Listener invocations\n  * Added overrideGroupsFromCliInParentChildXml test\n  * Ensure thread safety for attribute access\n  * Added @inherited to the Listeners annotation\n  * Restrict Group inheritance to Before|AfterGroups\n  * Ensure ITestResult injected to @AfterMethod is apt\n  * Support suite level thread pools for data provider\n  * Favour CompletableFuture instead of PoolService\n  * Favour FutureTask for concurrency support\n  * Shared Threadpool for normal/datadriven tests.\n  * Abort for invalid combinations\n\n- Changes of version 7.8.0:\n\n  * [Feature] Not exception but warning if some (not all) of the given test names are not found in suite files.\n  * [Feature] Generate testng-results.xml per test suite\n  * [Feature] Allow test classes to define 'configfailurepolicy' at a per class level\n  * XmlTest index is not set for test suites invoked with YAML\n  * Listener's onAfterClass is called before @afterclass configuration methods are executed.\n  * After upgrading to TestNG 7.5.0, setting ITestResult.status to FAILURE doesn't fail the test anymore\n  * JUnitReportReporter should capture the test case output at the test case level\n  * TestNG.xml doesn't honour Parallel value of a clone\n  * before configuration and before invocation should be 'SKIP' when beforeMethod is 'skip'\n  * Test listeners specified in parent testng.xml file are not included in testng-failed.xml file\n  * Discrepancies with DataProvider and Retry of failed tests\n  * Skipped Tests with DataProvider appear as failed\n  * testng-results xml reports config skips from base classes as ignored\n  * Feature: Check that specific object present in List\n  * Upgraded snakeyaml to 2.0\n\n- Changes of version 7.7.1:\n\n  * Streamline overloaded assertion methods for Groovy\n\n- Changes of version 7.7.0:\n\n  * Replace FindBugs by SpotBugs\n  * Gradle: Drop forUseAtConfigurationTime()\n  * Added ability to provide custom message to assertThrows\\expectThrows methods\n  * Only resolve hostname once\n  * Prevent overlogging of debug msgs in Graph impl\n  * Streamlined dataprovider invoking in abstract classes\n  * Streamlined TestResult due to expectedExceptions\n  * Unexpected test runs count with retry analyzer\n  * Make PackageUtils compliant with JPMS\n  * Ability to retry a data provider during failures\n  * Fixing bug with DataProvider retry\n  * Added config key for callback discrepancy behavior\n  * Fixed FileAlreadyExistsException error on copy\n  * JarFileUtils.delete(File f) throw actual exception (instead of FileNotFound) when file cannot be deleted #2825\n  * Changing assertion message of the osgitest\n  * Enhancing the Matrix\n  * Avoid Compilation errors on Semeru JDK flavour.\n  * Add addition yml extension\n  * Support getting dependencies info for a test\n  * Honour regex in dependsOnMethods\n  * Ensure All tests run all the time\n  * Deprecate support for running Spock Tests\n  * Streamline dependsOnMethods for configurations\n  * Ensure ITestContext available for JUnit4 tests\n  * Deprecate support for running JUnit tests\n  * Changes of 7.6.1\n  * Fix Files.copy() such that parent dirs are created\n  * Remove deprecated utility methods\n\n- Changes of version 7.6.0:\n\n  * Remove redundant Parameter implementation\n  * Upgraded to JDK11\n  * Move SimpleBaseTest to be Kotlin based\n  * Restore testnames when using suites in suite.\n  * Moving ClassHelperTests into Kotlin\n  * IHookable and IConfigurable callback discrepancy\n  * Minor refactoring\n  * Add additional condition for assertEqualsNoOrder\n  * beforeConfiguration() listener method should be invoked for skipped configurations as well\n  * Keep the initial order of listeners\n  * SuiteRunner could not be initial by default Configuration\n  * Enable Dataprovider failures to be considered.\n  * BeforeGroups should run before any matched test\n  * Fixed possible StringIndexOutOfBoundsException exception in XmlReporter\n  * DataProvider: possibility to unload dataprovider class, when done with it\n  * Fixed possibilty that AfterGroups method is invoked before all tests\n  * Fixed equals implementation for WrappedTestNGMethod\n  * Wire-In listeners consistently\n  * Streamline AfterClass invocation\n  * Show FQMN for tests in console\n  * Honour custom attribute values in TestNG default reports\n\n","modified":"2026-02-04T04:00:24.212141Z","published":"2024-07-22T03:19:30Z","related":["CVE-2022-4065"],"upstream":["CVE-2022-4065"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20242568-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-4065"}],"affected":[{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP5","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP5","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP6","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP6","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"mockito","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP6","purl":"pkg:rpm/suse/mockito&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.11.0-150200.3.7.1"}]}],"ecosystem_specific":{"binaries":[{"mockito":"5.11.0-150200.3.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Manager Server Module 4.3","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Manager%20Server%20Module%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"testng":"7.10.1-150200.3.10.1","snakeyaml":"2.2-150200.3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Server 15 SP3-LTSS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Server 15 SP3-LTSS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP3","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP3","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/testng&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"SUSE:Enterprise Storage 7.1","purl":"pkg:rpm/suse/snakeyaml&distro=SUSE%20Enterprise%20Storage%207.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"SUSE:Enterprise Storage 7.1","purl":"pkg:rpm/suse/testng&distro=SUSE%20Enterprise%20Storage%207.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml":"2.2-150200.3.15.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"mockito","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/mockito&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.11.0-150200.3.7.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml-javadoc":"2.2-150200.3.15.1","snakeyaml":"2.2-150200.3.15.1","testng-javadoc":"7.10.1-150200.3.10.1","testng":"7.10.1-150200.3.10.1","mockito-javadoc":"5.11.0-150200.3.7.1","mockito":"5.11.0-150200.3.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/snakeyaml&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"testng-javadoc":"7.10.1-150200.3.10.1","testng":"7.10.1-150200.3.10.1","mockito-javadoc":"5.11.0-150200.3.7.1","mockito":"5.11.0-150200.3.7.1","snakeyaml-javadoc":"2.2-150200.3.15.1","snakeyaml":"2.2-150200.3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/testng&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"snakeyaml-javadoc":"2.2-150200.3.15.1","snakeyaml":"2.2-150200.3.15.1","testng-javadoc":"7.10.1-150200.3.10.1","testng":"7.10.1-150200.3.10.1","mockito-javadoc":"5.11.0-150200.3.7.1","mockito":"5.11.0-150200.3.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"mockito","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/mockito&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.11.0-150200.3.7.1"}]}],"ecosystem_specific":{"binaries":[{"mockito-javadoc":"5.11.0-150200.3.7.1","mockito":"5.11.0-150200.3.7.1","snakeyaml-javadoc":"2.2-150200.3.15.1","snakeyaml":"2.2-150200.3.15.1","testng-javadoc":"7.10.1-150200.3.10.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"snakeyaml","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/snakeyaml&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2-150200.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"testng":"7.10.1-150200.3.10.1","mockito-javadoc":"5.11.0-150200.3.7.1","mockito":"5.11.0-150200.3.7.1","snakeyaml-javadoc":"2.2-150200.3.15.1","snakeyaml":"2.2-150200.3.15.1","testng-javadoc":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}},{"package":{"name":"testng","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/testng&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.10.1-150200.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"mockito-javadoc":"5.11.0-150200.3.7.1","mockito":"5.11.0-150200.3.7.1","snakeyaml-javadoc":"2.2-150200.3.15.1","snakeyaml":"2.2-150200.3.15.1","testng-javadoc":"7.10.1-150200.3.10.1","testng":"7.10.1-150200.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2568-1.json"}}],"schema_version":"1.7.3"}