CVE-2018-1051: Input Validation
Published Jan 17, 2018
·Updated
It was found that fix for CVE-2016-9606 was incomplete and Yaml unmarshalling in Resteasy is still possible via Yaml.load() in YamlProvider.
Other sources
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via Yaml.load() in YamlProvider.
— MITRE
Affected Software
2 affected components
redhat resteasy=3.0.22
redhat resteasy=3.1.2
Event History
Jan 17, 2018
Data Sourced
10:42 AM
DescriptionSeverityAffected Software
Jan 25, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1051.
2
What is the severity rating of CVE-2018-1051?
The severity rating of CVE-2018-1051 is high (8.1).
3
Which software versions are affected by CVE-2018-1051?
Versions 3.0.22 and 3.1.2 of Redhat Resteasy are affected by CVE-2018-1051.
4
How can the vulnerability be exploited?
The vulnerability can be exploited via Yaml unmarshalling in Resteasy's YamlProvider using `Yaml.load()`.
5
Is there a fix available for CVE-2018-1051?
Yes, the fix for CVE-2018-1051 is available. Please refer to the provided references for more information.