296,733
Total vulnerabilities in the database
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
| Software | From | Fixed in |
|---|---|---|
com.thoughtworks.xstream / xstream
|
- | 1.4.6 |
| xstream / xstream | 1.4.10 | 1.4.10.x |
| xstream_project / xstream | - | 1.4.6.x |