VDB
Sign up
CRITICAL9.8

GHSA-hf23-9pf7-388p

Deserialization of Untrusted Data and Code Injection in xstream

Quick fix

GHSA-hf23-9pf7-388p — com.thoughtworks.xstream:xstream: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.4.11</version> for com.thoughtworks.xstream:xstream

Details

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.thoughtworks.xstream:xstream
Introduced in: 1.4.10Fixed in: 1.4.11
Fix# pom.xml: bump <version>1.4.11</version> for com.thoughtworks.xstream:xstream

References