pkg:Maven/com.thoughtworks.xstream:xstream
37 total CVEsCRITICAL2HIGH22MEDIUM13
✅ Check your installed version
All known vulnerabilities
- from 0, < 1.4.18
- >= 1.4.10, < 1.4.11
- from 0, < 1.4.7
- from 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.18
- HIGH8.5CVE-2021-39150A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local hostfrom 0, < 1.4.18
- from 0, < 1.4.18
- HIGH8.5CVE-2021-39152A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local hostfrom 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.18
- from 0, < 1.4.20
- from 0, < 1.4.14-java7
- HIGH7.5CVE-2024-47072XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input streamfrom 0, < 1.4.21
- HIGH7.5CVE-2022-40151XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflowfrom 0, < 1.4.20
- from 0, < 1.4.19
- from 0, < 1.4.17
- from 0, < 1.4.16
- from 0, < 1.4.10
- from 0, < 1.4.9
- MEDIUM6.8CVE-2020-26259XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshallingfrom 0, < 1.4.15
- from 0, < 1.4.18
- from 0, < 1.4.15
- MEDIUM6.1CVE-2021-21349A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local hostfrom 0, < 1.4.16
- from 0, < 1.4.16
- from 0, < 1.4.16
- from 0, < 1.4.16
- from 0, < 1.4.16
- from 0, < 1.4.16
- MEDIUM5.3CVE-2021-21348XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)from 0, < 1.4.16
- from 0, < 1.4.16
- MEDIUM5.3CVE-2021-21343XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rightsfrom 0, < 1.4.16
- MEDIUM5.3CVE-2021-21342A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local hostfrom 0, < 1.4.16