Hint 2 Take a look at this blogpost for some explanation https://snyk.io/blog/unsafe-deserialization-snakeyaml-java-cve-2022-1471/