Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9606

Опубликовано: 09 мар. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 8.1

Описание

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

РелизСтатусПримечание
artful

ignored

end of life
bionic

DNE

cosmic

DNE

devel

not-affected

3.1.4-1
disco

not-affected

3.1.4-1
eoan

not-affected

3.1.4-1
esm-apps/focal

not-affected

3.1.4-1
esm-apps/jammy

not-affected

3.1.4-1
esm-apps/noble

not-affected

3.1.4-1
esm-apps/xenial

ignored

see notes and CVE-2018-1051

Показывать по

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
около 9 лет назад

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

CVSS3: 8.1
nvd
почти 8 лет назад

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

CVSS3: 8.1
debian
почти 8 лет назад

JBoss RESTEasy before version 3.1.2 could be forced into parsing a req ...

CVSS3: 8.1
github
больше 3 лет назад

JBoss RESTEasy vulnerable to Improper Input Validation

CVSS3: 8.1
fstec
около 9 лет назад

Уязвимость компонента YamlProvider программного средства RESTEasy, позволяющая нарушителю выполнить произвольный код

6.8 Medium

CVSS2

8.1 High

CVSS3