CVE-2013-7285
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 84.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 84.36% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- oracle/endeca information discovery studio · apache/activemq · xstream/xstream
- Source
- cve@mitre.org
References
- http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.htmlBroken Link, Not Applicable, URL Repurposed
- http://seclists.org/oss-sec/2014/q1/69Mailing List, Third Party Advisory
- http://web.archive.org/web/20140204133306/http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.htmlThird Party Advisory
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3EMailing List
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3EMailing List
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00604.htmlThird Party Advisory
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00607.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://x-stream.github.io/CVE-2013-7285.htmlExploit, Third Party Advisory
- http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.htmlBroken Link, Not Applicable, URL Repurposed
- http://seclists.org/oss-sec/2014/q1/69Mailing List, Third Party Advisory
- http://web.archive.org/web/20140204133306/http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.htmlThird Party Advisory
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3EMailing List
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3EMailing List
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00604.htmlThird Party Advisory
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00607.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://x-stream.github.io/CVE-2013-7285.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.