Описание
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
Ссылки
- PatchThird Party Advisory
- MitigationThird Party Advisory
- Issue TrackingMailing List
- Issue TrackingMailing List
- Issue TrackingMailing List
- Issue TrackingMailing List
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Not ApplicableThird Party Advisory
- Not ApplicableThird Party Advisory
- PatchThird Party Advisory
- ExploitMitigationVendor Advisory
- PatchThird Party Advisory
- MitigationThird Party Advisory
- Issue TrackingMailing List
- Issue TrackingMailing List
- Issue TrackingMailing List
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
EPSS
8 High
CVSS3
8.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
XStream before version 1.4.14 is vulnerable to Remote Code Execution.T ...
EPSS
8 High
CVSS3
8.8 High
CVSS3
9.3 Critical
CVSS2