Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-13480

[7.1] Development guide for Webservices - Yaml provider note that it is not recommended

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Major Major
    • None
    • 7.1.0.CR2
    • Documentation
    • None

      Book: Developing applications for Web Services
      Chapter: 2.5.13. YAML Provider

      Could you please add a note which says that it is not recommended to use yaml provider because of the security vulnerability:

      RESTEasy has a provider for YAML using the SnakeYAML library.
      The usage of the module is not recommended due to security issue in SnakeYAML library used by RESTEasy for unmarshaling. If you want to enable this anyway,
      you must update the following dependencies into the project POM file of your application...

            rhn-engineering-nchaudha Nidhi Chaudhary
            kanovotn Katerina Odabasi (Inactive)
            Katerina Odabasi Katerina Odabasi (Inactive)
            Katerina Odabasi Katerina Odabasi (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: