CVE-2016-9606
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.92% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/resteasy
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2017-1255.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1409.htmlThird Party Advisory
- http://www.securityfocus.com/bid/94940Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038524Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1253Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1254Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1256Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1410Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1411Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1412Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1675Broken Link, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1676Broken Link, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2909
- https://access.redhat.com/errata/RHSA-2018:2913
- https://bugzilla.redhat.com/show_bug.cgi?id=1400644Issue Tracking, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1255.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1409.htmlThird Party Advisory
- http://www.securityfocus.com/bid/94940Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038524Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1253Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1254Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1256Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1410Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1411Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1412Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1675Broken Link, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1676Broken Link, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2909
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.