Applications using Oracle Helidon versions 0.9.x, 0.10.x, 0.11.x, 1.0.x, 1.1.x, 1.2.x, 1.3.x, 1.4.x, 2.0.0-M1, 2.0.0-M2, 2.0.0-M3, 2.0.0-M4 and 2.0.0-RC1 are affected by a remote code execution vulnerability caused by insecure YAML deserialization when using the class UrlConfigSource for loading configuration files remotely.
This video shows PoC showing you can abuse loadAs() even if it's mapped to the class Map in the latest version of SnakeYAML (1.30 ATM)
More info:
https://websec.ca/publication/Blog/CV...
https://github.com/cldrn/security-adv...
https://github.com/cldrn/security-adv...