What the vulnerability does

01Description

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

Key dates

02Disclosure timeline

March 9, 2018 CVE published
September 16, 2024 Record updated