Back

CRITICAL

XStream: remote code execution due to insecure XML deserialization

Published May 15, 2019

Description

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 15, 2019
Updated Aug 6, 2024
Reserved Jan 9, 2014
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 22, 2013
GHSA-F554-X222-WGF7