First published: Wed Jan 17 2018(Updated: )
It was found that fix for <a href="https://access.redhat.com/security/cve/CVE-2016-9606">CVE-2016-9606</a> was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat RESTEasy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1535411 is considered high due to incomplete fixes for Yaml unmarshalling issues.
To fix REDHAT-BUG-1535411, you should apply the latest security updates and patches provided by Red Hat.
Symptoms of REDHAT-BUG-1535411 may include vulnerabilities in Yaml unmarshalling that could lead to potential code execution.
REDHAT-BUG-1535411 affects various versions of Red Hat Resteasy that utilize YamlProvider.
Yes, REDHAT-BUG-1535411 can potentially lead to security breaches through unsafe Yaml unmarshalling.