ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-24621
+1 in the same advisory: …24620
An issue was discovered in Esoteric YamlBeans through 1.15.

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • esotericsoftware yamlbeans