XStream 1.4.10

CPE Details

XStream 1.4.10
1.4.10
2025-04-01
11h07 +00:00
2025-04-01
11h07 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:x-stream:xstream:1.4.10:*:*:*:*:*:*:*

Informations

Vendor

x-stream

Product

xstream

Version

1.4.10

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-10173 2019-07-23 10h50 +00:00 It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
9.8
Critique
CVE-2013-7285 2019-05-15 14h54 +00:00 Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
9.8
Critique