Lack of data validation In org.jboss.resteasy:resteasy-bom
Description
JBoss RESTEasy vulnerable to Improper Input Validation JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.1.2.final | ||
debian 12 | 3.0.26-1 | ||
debian 11 | 3.0.26-1 | ||
debian 13 | 3.0.26-1 | ||
debian 14 | 3.0.26-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17.
References
1. 2. 3. 4. 5. 6.