maven

com.thoughtworks.xstream:xstream

View on maven registry
38 Total advisories
38 Vulnerabilities
0 Malware

Dependency scanning

Check whether com.thoughtworks.xstream:xstream is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.5
Maven

CVE-2021-39148

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.3
Maven

CVE-2021-21344

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 6.1
Maven

CVE-2021-21349

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

MEDIUM 5.3
Maven

CVE-2021-21343

XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights

HIGH 7.5
Maven

CVE-2021-21341

XStream can cause a Denial of Service.

MEDIUM 6.1
Maven

CVE-2021-21346

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39141

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 7.5
Maven

CVE-2021-43859

Denial of Service by injecting highly recursive collections or maps in XStream

HIGH 8.5
Maven

CVE-2021-39150

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

MEDIUM 6.1
Maven

CVE-2021-21347

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39146

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39147

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39145

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.3
Maven

CVE-2021-21342

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

MEDIUM 5.8
Maven

CVE-2021-21345

XStream is vulnerable to a Remote Command Execution attack

HIGH 7.5
Maven

CVE-2021-29505

XStream is vulnerable to a Remote Command Execution attack

HIGH 8.5
Maven

CVE-2021-39151

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39153

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39139

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39149

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39154

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.3
Maven

CVE-2021-21350

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.4
Maven

CVE-2021-21351

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 6.5
Maven

CVE-2021-39140

XStream can cause a Denial of Service

HIGH 8.5
Maven KEV

CVE-2021-39144

XStream is vulnerable to a Remote Command Execution attack

MEDIUM 5.3
Maven

CVE-2021-21348

XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)

HIGH 8.5
Maven

CVE-2021-39152

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

HIGH 8.0
Maven

CVE-2020-26217

XStream can be used for Remote Code Execution

MEDIUM 6.8
Maven

CVE-2020-26259

XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling

MEDIUM 6.3
Maven

CVE-2020-26258

Server-Side Forgery Request can be activated unmarshalling with XStream

CRITICAL 9.8
Maven

CVE-2019-10173

Deserialization of Untrusted Data and Code Injection in xstream

HIGH 7.5
Maven

CVE-2024-47072

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

HIGH 7.5
Maven

CVE-2017-7957

Denial of service in XStream

HIGH 7.5
Maven

CVE-2016-3674

XML External Entity Injection in XStream

UNKNOWN
Maven

GHSA-3mq5-fq9h-gj7j

Duplicate Advisory: Denial of Service due to parser crash

CRITICAL 9.8
Maven

CVE-2013-7285

Command Injection in Xstream

HIGH 8.2
Maven

CVE-2022-41966

XStream can cause Denial of Service via stack overflow

HIGH 7.5
Maven

CVE-2022-40151

XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes