Description
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1535411
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13
CVE-2017-16008 Vulnerability in maven package org.webjars.npm:i18next
CVE-2022-25948 Vulnerability in npm package liquidjs
CVE-2019-10240 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-parent