XStream.Library.CVE-2020-26217.Insecure.Deserialization
Description
This indicates an attack attempt to exploit an Insecure Deserialization Vulnerability in XStream.
The vulnerability is due to improper validation of user input during unmarshalling of XML and JSON data. A remote attacker could exploit this vulnerability by sending specially crafted XML or JSON data to the affected application. Successful exploitation could allow the attacker to execute arbitrary command under the security context of the application implementing the library.
Affected Products
XStream XStream prior to 1.4.14
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |