Total vulnerabilities in the database
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Software | From | Fixed in |
---|---|---|
![]() |
- | 1.4.6 |
xstream / xstream | 1.4.10 | 1.4.10.x |
xstream_project / xstream | - | 1.4.6.x |