Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12408
HistoryJan 15, 2019 - 9:16 a.m.

Remote Code Execution (RCE)

2019-01-1509:16:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.017

Percentile

87.9%

RESTEasy is vulnerable to remote code execution. SnakeYAML unmarshalling is exploitable for code execution. As RESTeasy uses SnakeYAML and enables the yaml provider by default, under certain conditions, RESTEasy could be forced to parse a request with YamlProvider, resulting in unmarshalling of potentially untrusted data. An attacker can exploit it to execute arbitrary code with the permissions of the application using RESTEasy.