PT-2019-2961 · Xstream · Xstream

Published

2019-06-21

·

Updated

2025-05-14

·

CVE-2019-10173

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XStream versions 1.4.10 through 1.4.10
Description The issue is related to a regression of a previous deserialization flaw in the XStream API. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format, such as JSON. This could be exploited by a remote attacker to execute arbitrary commands.
Recommendations For XStream version 1.4.10, update to version 1.4.11 to resolve the issue. As a temporary workaround, consider initializing the security framework before using the XStream API to minimize the risk of exploitation. Restrict access to unmarshalling XML or other supported formats until the issue is resolved.

Fix

Code Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02936
CVE-2019-10173
GHSA-HF23-9PF7-388P

Affected Products

Xstream