VYPR
High severityNVD Advisory· Published Jan 25, 2018· Updated Aug 5, 2024

CVE-2018-1051

CVE-2018-1051

Description

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via Yaml.load() in YamlProvider.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jboss.resteasy:resteasy-yaml-providerMaven
< 3.0.26.Final3.0.26.Final
org.jboss.resteasy:resteasy-yaml-providerMaven
>= 3.1.0, < 3.6.0.Final3.6.0.Final

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.