CVE-2016-8744 is a critical deserialization vulnerability affecting Apache Brooklyn versions prior to 0.10.0, stemming from its use of the SnakeYAML library. An authenticated attacker could exploit this by providing specially crafted YAML input, allowing the unmarshalling of arbitrary Java types. This could lead to remote code execution with the privileges of the Brooklyn JVM, enabling file system access, network connections, and system command execution. While a proof-of-concept exploit is known to exist, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.0CPE matchmatch criteria | cpe:2.3:a:apache:brooklyn:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.