Описание
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
It was found that xstream API version 1.4.10 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. This a regression of CVE-2013-7285 fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | xstream | Affected | ||
| Red Hat Data Grid 7.3.3 | xstream | Fixed | RHSA-2020:0727 | 05.03.2020 |
| Red Hat Fuse 6.3 | xstream | Fixed | RHSA-2019:4352 | 19.12.2019 |
| Red Hat Fuse 7.5.0 | Fixed | RHSA-2019:3892 | 14.11.2019 | |
| Red Hat JBoss BPMS 7.4 | xstream | Fixed | RHSA-2019:1823 | 22.07.2019 |
| Red Hat JBoss BRMS 7.4 | xstream | Fixed | RHSA-2019:1822 | 22.07.2019 |
| Red Hat Single Sign-On 7.3 | rh-sso7-keycloak | Fixed | RHSA-2020:0445 | 06.02.2020 |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
It was found that xstream API version 1.4.10 before 1.4.11 introduced ...
Deserialization of Untrusted Data and Code Injection in xstream
Уязвимость Java-библиотеки для преобразования объектов в XML или JSON формат XStream, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольные команды
7.3 High
CVSS3