CVE Published: 09/03/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2016 Source: redhat |
Vendor: Red Hat, Inc. |
Product: RESTEasy Status : PUBLISHED
CVE-2016-9606 Description
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.