XML External Entity Injection in XStream
High severity
GitHub Reviewed
Published
Jun 30, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 30, 2020
Published to the GitHub Advisory Database
Jun 30, 2020
Last updated
Jan 9, 2023
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
References