Vulnerabilities > CVE-2023-24621 - Deserialization of Untrusted Data vulnerability in Esotericsoftware Yamlbeans

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
esotericsoftware
CWE-502

Summary

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

Common Weakness Enumeration (CWE)