View all vulnerabilities

CVE-2013-7285

Command Injection in Xstream

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
9.8
Score Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
com.thoughtworks.xstream:xstream < 1.4.7; com.thoughtworks.xstream:xstream >= 1.4.10 < 1.4.11
Severity
Ecosystem
Publish Date
May 29, 2019
Modified Date
March 4, 2024