RULE(RULE ID:322858)

Rule General Information
Release Date: 2019-08-13
Rule Name: XStream Library ReflectionConverter Insecure Deserialization Vulnerability (CVE-2019-10173)
Severity:
CVE ID:
Rule Protection Details
Description: It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Others
Reference: http://x-stream.github.io/changes.html#1.4.11
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10173
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://x-stream.github.io/