GHSA-m2fv-3rqm-g7p5
Dashboard / Vulnerabilities / GHSA-m2fv-3rqm-g7p5
Summary: Deserialization of Untrusted Data in org.jboss.resteasy:resteasy-yaml-provider
Details: It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider. #### Mitigation: If the YamlProvider is enabled it's recommended to add authentication, and authorization to the endpoint expecting Yaml content to prevent exploitation of this vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1051, https://github.com/resteasy/resteasy/pull/1555, https://bugzilla.redhat.com/show_bug.cgi?id=1535411, https://bugzilla.redhat.com/show_bug.cgi?id=1539175#c3
Affected packages
Package
Name: org.jboss.resteasy:resteasy-yaml-provider
Purl: pkg:maven/org.jboss.resteasy/resteasy-yaml-provider
Affected ranges
Type: ECOSYSTEM
Events:
