JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an malicious user to execute arbitrary code with RESTEasy application permissions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat resteasy |