QID 981787

QID 981787: Java (maven) Security Update for com.thoughtworks.xstream:xstream (GHSA-f554-x222-wgf7)

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-f554-x222-wgf7 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981787

    Software Advisories
    Advisory ID Software Component Link
    GHSA-f554-x222-wgf7 com.thoughtworks.xstream:xstream URL Logo github.com/advisories/GHSA-f554-x222-wgf7