Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Activemq
Subscribe
|
|
Oracle
Subscribe
|
Endeca Information Discovery Studio
Subscribe
|
|
Redhat
Subscribe
|
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Data Grid
Subscribe
Jboss Data Virtualization
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Rhev Manager
Subscribe
|
|
Xstream
Subscribe
|
Xstream
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f554-x222-wgf7 | Command Injection in Xstream |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 23 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache activemq Oracle Oracle endeca Information Discovery Studio |
|
| CPEs | cpe:2.3:a:apache:activemq:5.15.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:* cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Xstream Project
Xstream Project xstream |
Apache
Apache activemq Oracle Oracle endeca Information Discovery Studio |
Wed, 14 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xstream
Xstream xstream |
|
| CPEs | cpe:2.3:a:xstream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
X-stream
X-stream xstream |
Xstream
Xstream xstream |
Tue, 01 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
X-stream
X-stream xstream |
|
| CPEs | cpe:2.3:a:x-stream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
X-stream
X-stream xstream |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T18:01:20.408Z
Reserved: 2014-01-09T00:00:00.000Z
Link: CVE-2013-7285
No data.
Status : Analyzed
Published: 2019-05-15T17:29:00.297
Modified: 2025-05-23T16:54:47.330
Link: CVE-2013-7285
OpenCVE Enrichment
No data.
Github GHSA