Description
An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.
Remediation
References
https://contrastsecurity.com
https://github.com/Contrast-Security-OSS/yamlbeans/blob/main/SECURITY.md
https://github.com/EsotericSoftware
Related Vulnerabilities
CVE-2019-15782 Vulnerability in maven package org.webjars.npm:webtorrent
CVE-2019-6002 Vulnerability in maven package com.linecorp.centraldogma:centraldogma-server
CVE-2015-2918 Vulnerability in maven package com.orientechnologies:orientdb-studio
CVE-2023-3691 Vulnerability in maven package org.webjars.bower:layui
CVE-2019-10396 Vulnerability in maven package org.jenkins-ci.plugins:dashboard-view