Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Rui Chong

Pesquisador deBaidu
#31499de 53,639
8.1CVSS total
Vulnerabilidades · 1
PT-2018-9931
8.1
2018-01-25
Red Hat · Resteasy · CVE-2018-1051
Name of the Vulnerable Software and Affected Versions: Resteasy versions 3.0.22 and 3.1.2 Description: The issue is related to incomplete fixing of a previous problem in Yaml unmarshalling within Resteasy, allowing it to still occur via `Yaml.load()` in YamlProvider. Recommendations: For versions 3.0.22 and 3.1.2, if the YamlProvider is enabled, add authentication and authorization to the endpoint expecting Yaml content to prevent exploitation of this issue.