Back

HIGH

Resteasy: Yaml unmarshalling vulnerable to RCE

Published Mar 9, 2018

Description

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

Affected products

Remediation

Red Hat statement

YamlProvider was removed the default list of providers to prevent a malicous user from requesting a payload be marshalled with Yaml. If marshalling of Yaml content is desired, add, or append a file with the name 'META-INF/services/javax.ws.rs.ext.Providers' to your WAR, or JAR with the contents 'org.jboss.resteasy.plugins.providers.YamlProvider' If YamlProvider is re-added to the default list of providers it's recommended to add authentication, and authorization to the endpoint expecting Yaml content to prevent exploitation of this vulnerablilty.

Red Hat mitigation

Add authentication and authorization to any Resteasy endpoint which doesn't define a mime type, or defines a multipart mime type.

Metrics

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 9, 2018
Updated Sep 16, 2024
Reserved Nov 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 15, 2016
GHSA-HGJR-XWJ3-JFVW