Command Injection in Xstream
Critical severity
GitHub Reviewed
Published
May 29, 2019
to the GitHub Advisory Database
•
Updated Mar 4, 2024
Package
Affected versions
< 1.4.7
= 1.4.10
Patched versions
1.4.7
1.4.11
Description
Published by the National Vulnerability Database
May 15, 2019
Reviewed
May 15, 2019
Published to the GitHub Advisory Database
May 29, 2019
Last updated
Mar 4, 2024
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
References