logo

Database

Insecure deserialization In com.thoughtworks.xstream:xstream

Description

Deserialization of Untrusted Data and Code Injection in xstream It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-91XRP – Vulnerability | Fluid Attacks Database