Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2fv-3rqm-g7p5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Deserialization of Untrusted Data in org.jboss.resteasy:resteasy-yaml-provider

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via Yaml.load() in YamlProvider.

Mitigation:

If the YamlProvider is enabled it's recommended to add authentication, and authorization to the endpoint expecting Yaml content to prevent exploitation of this vulnerability.

Пакеты

Наименование

org.jboss.resteasy:resteasy-yaml-provider

maven
Затронутые версииВерсия исправления

< 3.0.26.Final

3.0.26.Final

Наименование

org.jboss.resteasy:resteasy-yaml-provider

maven
Затронутые версииВерсия исправления

>= 3.1.0, < 3.6.0.Final

3.6.0.Final

EPSS

Процентиль: 71%
0.00688
Низкий

8.1 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

CVSS3: 8.1
redhat
около 8 лет назад

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

CVSS3: 8.1
nvd
около 8 лет назад

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

CVSS3: 8.1
debian
около 8 лет назад

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1 ...

EPSS

Процентиль: 71%
0.00688
Низкий

8.1 High

CVSS3

Дефекты

CWE-502