296,746
Total vulnerabilities in the database
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via Yaml.load() in YamlProvider.
| Software | From | Fixed in |
|---|---|---|
| redhat / resteasy | 3.1.2 | 3.1.2.x |
| redhat / resteasy | 3.0.22 | 3.0.22.x |
org.jboss.resteasy / resteasy-yaml-provider
|
- | 3.0.26.Final |
org.jboss.resteasy / resteasy-yaml-provider
|
3.1.0 | 3.6.0.Final |