Uploaded image for project: 'mod-circulation'
  1. mod-circulation
  2. CIRC-1086

xstream 1.4.15 fixing Arbitrary File Deletion vulnerability (CVE-2020-26259)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • 19.2.8
    • 20.0.0
    • 0.5
    • None

    Description

      Overview:

      XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights.

      All versions until and including version 1.4.14 are affected running in a Java environment containing the JAX-WS runtime, if using the version out of the box.

      Details: https://x-stream.github.io/CVE-2020-26259.html

      Fix:

      Update the XStream version from 1.4.14 to 1.4.15.

      TestRail: Results

        Attachments

          Activity

            People

              julianladisch Julian Ladisch
              julianladisch Julian Ladisch
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases