XStream.Library.CVE-2020-26217.Insecure.Deserialization

description-logoDescription

This indicates an attack attempt to exploit an Insecure Deserialization Vulnerability in XStream.
The vulnerability is due to improper validation of user input during unmarshalling of XML and JSON data. A remote attacker could exploit this vulnerability by sending specially crafted XML or JSON data to the affected application. Successful exploitation could allow the attacker to execute arbitrary command under the security context of the application implementing the library.

affected-products-logoAffected Products

XStream XStream prior to 1.4.14

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2021-06-08 18.094
Modified
Default_action:pass:drop
2021-05-25 18.084
New