QID 981787
QID 981787: Java (maven) Security Update for com.thoughtworks.xstream:xstream (GHSA-f554-x222-wgf7)
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f554-x222-wgf7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-f554-x222-wgf7 -
github.com/advisories/GHSA-f554-x222-wgf7
CVEs related to QID 981787
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f554-x222-wgf7 | com.thoughtworks.xstream:xstream |
|