It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
X-stream
X-stream xstream |
|
CPEs | cpe:2.3:a:x-stream:xstream:1.4.10:*:*:*:*:*:*:* | |
Vendors & Products |
Xstream Project
Xstream Project xstream |
X-stream
X-stream xstream |

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:10.018Z
Reserved: 2019-03-27T00:00:00
Link: CVE-2019-10173

No data.

Status : Modified
Published: 2019-07-23T13:15:13.177
Modified: 2025-04-01T13:07:22.907
Link: CVE-2019-10173
