Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1535411 - (CVE-2018-1051) CVE-2018-1051 resteasy: Unsafe unmarshalling in YamlProvider allows code execution
CVE-2018-1051 resteasy: Unsafe unmarshalling in YamlProvider allows code exec...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180118,repor...
: Security
Depends On: 1539175 1598370 1536223 1539176 1539177 1539178 1539179
Blocks: 1535413
  Show dependency treegraph
 
Reported: 2018-01-17 05:42 EST by Adam Mariš
Modified: 2018-10-19 17:45 EDT (History)
91 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Adam Mariš 2018-01-17 05:42:28 EST
It was found that fix for CVE-2016-9606 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.
Comment 3 Jason Shepherd 2018-01-18 02:02:43 EST
resteasy-yaml-provider is marked as unsupported here. Marking EAP 7 as not affected
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.0/paged/7.0.0_release_notes/release_notes_unsupported_and_deprecated_functionality
Comment 5 Jason Shepherd 2018-01-18 03:14:23 EST
Mitigation:

If the YamlProvider is enabled it's recommended to add authentication, and authorization to the endpoint expecting Yaml content to prevent exploitation of this vulnerability.
Comment 9 Jason Shepherd 2018-01-23 00:23:39 EST
This won't be fixed in JBoss EAP 6.4, or 7.1 as the YamlProvider in RESTEasy is unsupported.
Comment 10 Jason Shepherd 2018-01-23 22:41:08 EST
Acknowledgments:

Name: Rui Chong (Baidu)
Comment 12 Kurt Seifried 2018-01-26 15:03:57 EST
Created resteasy tracking bugs for this issue:

Affects: fedora-all [bug 1539175]
Comment 18 Doran Moppert 2018-07-05 04:45:41 EDT
Statement:

This issue only affects applications which have the YamlProvider explicitly enabled by adding or appending a file with the name 'META-INF/services/javax.ws.rs.ext.Providers' to your WAR, or JAR with the contents 'org.jboss.resteasy.plugins.providers.YamlProvider'

resteasy-base as shipped in Red Hat Enterprise Linux 7 does not include YamlProvider.

Red Hat Subscription Asset Manager version 1 is now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates.

This issue affects the versions of resteasy as shipped with Red Hat Satellite version 6, however Satellite version 6 does not use the affected functionality. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue.

For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Note You need to log in before you can comment on or make changes to this bug.