PoC Index

CVE-2023-24621

HIGH 7.8EPSS 0.5%

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.45% chance of exploitation in the next 30 days, 38th percentile
Published
2023-08-25
Updated
2024-10-02

Proof-of-concept exploits (1)

References

Related