Description
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hf23-9pf7-388p | Deserialization of Untrusted Data and Code Injection in xstream |
References
History
Wed, 14 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xstream
Xstream xstream |
|
| CPEs | cpe:2.3:a:xstream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
X-stream
X-stream xstream |
Xstream
Xstream xstream |
Tue, 01 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
X-stream
X-stream xstream |
|
| CPEs | cpe:2.3:a:x-stream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
Xstream Project
Xstream Project xstream |
X-stream
X-stream xstream |
Subscriptions
Oracle
Subscribe
Banking Platform
Subscribe
Business Activity Monitoring
Subscribe
Communications Billing And Revenue Management Elastic Charging Engine
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Studio
Subscribe
Retail Xstore Point Of Service
Subscribe
Utilities Framework
Subscribe
Webcenter Portal
Subscribe
Redhat
Subscribe
Jboss Bpms
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Single Sign On
Subscribe
Xstream
Subscribe
Xstream
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:10.018Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10173
No data.
Status : Modified
Published: 2019-07-23T13:15:13.177
Modified: 2025-05-14T20:02:54.240
Link: CVE-2019-10173
OpenCVE Enrichment
No data.
Github GHSA