Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-13480

[7.1] Development guide for Webservices - Yaml provider note that it is not recommended

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Major
    • None
    • 7.1.0.CR2
    • Documentation
    • None

    Description

      Book: Developing applications for Web Services
      Chapter: 2.5.13. YAML Provider

      Could you please add a note which says that it is not recommended to use yaml provider because of the security vulnerability:

      RESTEasy has a provider for YAML using the SnakeYAML library.
      The usage of the module is not recommended due to security issue in SnakeYAML library used by RESTEasy for unmarshaling. If you want to enable this anyway,
      you must update the following dependencies into the project POM file of your application...

      Attachments

        Issue Links

          Activity

            People

              rhn-engineering-nchaudha Nidhi Chaudhary
              kanovotn Katerina Odabasi (Inactive)
              Katerina Odabasi Katerina Odabasi (Inactive)
              Katerina Odabasi Katerina Odabasi (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: