Описание
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | DNE | |
| cosmic | DNE | |
| devel | not-affected | 3.1.4-1 |
| disco | not-affected | 3.1.4-1 |
| eoan | not-affected | 3.1.4-1 |
| esm-apps/focal | not-affected | 3.1.4-1 |
| esm-apps/jammy | not-affected | 3.1.4-1 |
| esm-apps/noble | not-affected | 3.1.4-1 |
| esm-apps/xenial | ignored | see notes and CVE-2018-1051 |
Показывать по
6.8 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
JBoss RESTEasy before version 3.1.2 could be forced into parsing a req ...
JBoss RESTEasy vulnerable to Improper Input Validation
Уязвимость компонента YamlProvider программного средства RESTEasy, позволяющая нарушителю выполнить произвольный код
6.8 Medium
CVSS2
8.1 High
CVSS3