Description
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f554-x222-wgf7 | Command Injection in Xstream |
References
History
Fri, 23 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache activemq Oracle Oracle endeca Information Discovery Studio |
|
| CPEs | cpe:2.3:a:apache:activemq:5.15.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:* cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Xstream Project
Xstream Project xstream |
Apache
Apache activemq Oracle Oracle endeca Information Discovery Studio |
Wed, 14 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xstream
Xstream xstream |
|
| CPEs | cpe:2.3:a:xstream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
X-stream
X-stream xstream |
Xstream
Xstream xstream |
Tue, 01 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
X-stream
X-stream xstream |
|
| CPEs | cpe:2.3:a:x-stream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
X-stream
X-stream xstream |
Subscriptions
Apache
Subscribe
Activemq
Subscribe
Oracle
Subscribe
Endeca Information Discovery Studio
Subscribe
Redhat
Subscribe
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Data Grid
Subscribe
Jboss Data Virtualization
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Rhev Manager
Subscribe
Xstream
Subscribe
Xstream
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T18:01:20.408Z
Reserved: 2014-01-09T00:00:00.000Z
Link: CVE-2013-7285
No data.
Status : Analyzed
Published: 2019-05-15T17:29:00.297
Modified: 2025-05-23T16:54:47.330
Link: CVE-2013-7285
OpenCVE Enrichment
No data.
Github GHSA