High severityNVD Advisory· Published Aug 25, 2023· Updated Oct 2, 2024
CVE-2023-24621
CVE-2023-24621
Description
An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.esotericsoftware.yamlbeans:yamlbeansMaven | <= 1.15 | — |
Affected products
2- Esoteric/YamlBeansdescription
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.