CVE-2023-24621
Last modified
CVE-2023-24621 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Esotericsoftware | Yamlbeans | <= 1.15 |
References
- https://contrastsecurity.comThird Party Advisory
- https://github.com/Contrast-Security-OSS/yamlbeans/blob/main/SECURITY.mdExploit, Third Party Advisory
- https://github.com/EsotericSoftwareThird Party Advisory
- https://contrastsecurity.comThird Party Advisory
- https://github.com/Contrast-Security-OSS/yamlbeans/blob/main/SECURITY.mdExploit, Third Party Advisory
- https://github.com/EsotericSoftwareThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-24621?
How severe is CVE-2023-24621?
How do I fix CVE-2023-24621?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-24610NOSH 4a5cfdb allows remote authenticated users to execute PH…8.8
- CVE-2023-24612The PdfBook extension through 2.0.5 before b07b6a64 for Medi…9.8
- CVE-2023-24613The user interface of Array Networks AG Series and vxAG thro…4.9
- CVE-2023-24619Redpanda before 22.3.12 discloses cleartext AWS credentials.…5.5
- CVE-2023-2462Inappropriate implementation in Prompts in Google Chrome pri…4.3
- CVE-2023-24620An issue was discovered in Esoteric YamlBeans through 1.15. …5.5
- CVE-2023-24622isInList in the safeurl-python package before 1.2 for Python…5.3
- CVE-2023-24623Paranoidhttp before 0.3.0 allows SSRF because [::] is equiva…7.5
- CVE-2023-24625Faveo 5.0.1 allows remote attackers to obtain sensitive info…6.5
- CVE-2023-24626socket.c in GNU Screen through 4.9.0, when installed setuid …6.5
- CVE-2023-2463Inappropriate implementation in Full Screen Mode in Google C…4.3
- CVE-2023-2464Inappropriate implementation in PictureInPicture in Google C…4.3
Are you affected by CVE-2023-24621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
