It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Project Subscriptions
| Vendors | Products |
|---|---|
|
Oracle
Subscribe
|
Banking Platform
Subscribe
Business Activity Monitoring
Subscribe
Communications Billing And Revenue Management Elastic Charging Engine
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Studio
Subscribe
Retail Xstore Point Of Service
Subscribe
Utilities Framework
Subscribe
Webcenter Portal
Subscribe
|
|
Redhat
Subscribe
|
|
|
Xstream
Subscribe
|
Xstream
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hf23-9pf7-388p | Deserialization of Untrusted Data and Code Injection in xstream |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 14 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xstream
Xstream xstream |
|
| CPEs | cpe:2.3:a:xstream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
X-stream
X-stream xstream |
Xstream
Xstream xstream |
Tue, 01 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
X-stream
X-stream xstream |
|
| CPEs | cpe:2.3:a:x-stream:xstream:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
Xstream Project
Xstream Project xstream |
X-stream
X-stream xstream |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:10.018Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10173
No data.
Status : Modified
Published: 2019-07-23T13:15:13.177
Modified: 2025-05-14T20:02:54.240
Link: CVE-2019-10173
OpenCVE Enrichment
No data.
Github GHSA