Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jm7r-4pg6-gf26: Esoteric YamlBeans Unsafe Deserialization vulnerability

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

ghsa
#vulnerability#git#java#auth

Esoteric YamlBeans Unsafe Deserialization vulnerability

High severity GitHub Reviewed Published Aug 25, 2023 to the GitHub Advisory Database • Updated Aug 25, 2023

Related news

CVE-2023-24621: yamlbeans/SECURITY.md at main · Contrast-Security-OSS/yamlbeans

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

ghsa: Latest News

GHSA-g84x-g96g-rcjc: Librenms has a reflected XSS on error alert