CRITICAL9.8
GHSA-hf23-9pf7-388p
Deserialization of Untrusted Data and Code Injection in xstream
Quick fix
GHSA-hf23-9pf7-388p — com.thoughtworks.xstream:xstream: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.4.11</version> for com.thoughtworks.xstream:xstreamDetails
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.thoughtworks.xstream:xstream
Introduced in:
1.4.10Fixed in: 1.4.11Fix
# pom.xml: bump <version>1.4.11</version> for com.thoughtworks.xstream:xstreamReferences
- https://nvd.nist.gov/vuln/detail/CVE-2019-10173[ADVISORY]
- https://access.redhat.com/errata/RHSA-2019:3892[WEB]
- https://access.redhat.com/errata/RHSA-2019:4352[WEB]
- https://access.redhat.com/errata/RHSA-2020:0445[WEB]
- https://access.redhat.com/errata/RHSA-2020:0727[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10173[WEB]
- https://github.com/x-stream/xstream[PACKAGE]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuApr2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuapr2020.html[WEB]
- https://www.oracle.com/security-alerts/cpujan2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuoct2020.html[WEB]
- http://x-stream.github.io/changes.html#1.4.11[WEB]