Back

HIGH

XStream: DoS when unmarshalling void type

Published Apr 29, 2017

Description

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 29, 2017
Updated Aug 5, 2024
Reserved Apr 19, 2017
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 3, 2017
GHSA-7HWC-46RM-65JH