CVE-2016-3674
published 2016-05-17CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6)…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
8.18%
94.2th percentile
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libxstream-java | < libxstream-java 1.4.9-1 (bookworm) | libxstream-java 1.4.9-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | jboss_middleware | — | — |
| xstream | xstream | < 1.4.9 | 1.4.9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libxstream-java vulnerabilities
osv·2024-08-22·CVSS 7.5
CVE-2016-3674 [HIGH] libxstream-java vulnerabilities
libxstream-java vulnerabilities
It was discovered that XStream incorrectly handled parsing of certain
crafted XML documents. A remote attacker could possibly use this issue to
read arbitrary files. (CVE-2016-3674)
Zhihong Tian and Hui Lu found that XStream was vulnerable to remote code
execution. A remote attacker could run arbitrary shell commands by
manipulating the processed input stream. (CVE-2020-26217)
It was discovered that XStream was vulnerable to server-side forgery
attacks. A remote attacker could request data from internal resources
that are not publicly available only by manipulating the processed input
stream. (CVE-2020-26258)
It was discovered that XStream was vulnerable to arbitrary file deletion
on the local host. A remote attacker could use this to delete arbitrary
kn
OSV
XML External Entity Injection in XStream
osv·2020-06-30
CVE-2016-3674 [HIGH] XML External Entity Injection in XStream
XML External Entity Injection in XStream
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
GHSA
XML External Entity Injection in XStream
ghsa·2020-06-30
CVE-2016-3674 [HIGH] CWE-200 XML External Entity Injection in XStream
XML External Entity Injection in XStream
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
OSV
CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Standa
osv·2016-05-17·CVSS 7.5
CVE-2016-3674 [HIGH] CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Standa
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Ubuntu
XStream vulnerabilities
vendor_ubuntu·2024-08-22·CVSS 7.5
CVE-2021-21342 [HIGH] XStream vulnerabilities
Title: XStream vulnerabilities
Summary: Several security issues were fixed in XStream.
It was discovered that XStream incorrectly handled parsing of certain
crafted XML documents. A remote attacker could possibly use this issue to
read arbitrary files. (CVE-2016-3674)
Zhihong Tian and Hui Lu found that XStream was vulnerable to remote code
execution. A remote attacker could run arbitrary shell commands by
manipulating the processed input stream. (CVE-2020-26217)
It was discovered that XStream was vulnerable to server-side forgery
attacks. A remote attacker could request data from internal resources
that are not publicly available only by manipulating the processed input
stream. (CVE-2020-26258)
It was discovered that XStream was vulnerable to arbitrary file deletion
on the local host.
Red Hat
XStream: enabled processing of external entities
vendor_redhat·2016-03-15·CVSS 7.5
CVE-2016-3674 [HIGH] CWE-611 XStream: enabled processing of external entities
XStream: enabled processing of external entities
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
It was found that several XML parsers used by XStream had default settings that would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: xstream (Red Hat BPM Suite 6) - Affected
Package: xstream (Red Hat Enterprise Linux 7) - Affected
Package: jasperreports-server-pro (Red Hat Enterprise Vi
Debian
CVE-2016-3674: libxstream-java - Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) D...
vendor_debian·2016·CVSS 7.5
CVE-2016-3674 [HIGH] CVE-2016-3674: libxstream-java - Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) D...
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Scope: local
bookworm: resolved (fixed in 1.4.9-1)
bullseye: resolved (fixed in 1.4.9-1)
forky: resolved (fixed in 1.4.9-1)
sid: resolved (fixed in 1.4.9-1)
trixie: resolved (fixed in 1.4.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]
bugzilla·2016-05-13·CVSS 7.5
CVE-2016-3674 [HIGH] CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]
CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]
+++ This bug was initially created as a clone of Bug #1321791 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]
bugzilla·2016-03-29·CVSS 7.5
CVE-2016-3674 [HIGH] CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]
CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2016-3674 XStream: enabled processing of external entities
bugzilla·2016-03-29·CVSS 7.5
CVE-2016-3674 [HIGH] CVE-2016-3674 XStream: enabled processing of external entities
CVE-2016-3674 XStream: enabled processing of external entities
XStream (x-stream.github.io) is a Java library to marshal Java objects into
XML and back. For this purpose it supports a lot of different XML parsers.
Some of those can also process external entities which was enabled by
default.
An attacker could therefore provide manipulated XML as input to access data
on the file system, see
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing
Discussion:
Created jenkins-xstream tracking bugs for this issue:
Affects: fedora-all [bug 1321792]
---
Created xstream tracking bugs for this issue:
Affects: fedora-all [bug 1321791]
---
External References:
https://github.com/x-stream/xstream/issues/25
---
xstream-1.4.9-1.fc24 has been pushed to the Fedora 24 stable repos
Bugzilla
CVE-2016-3674 jenkins-xstream: XStream: enabled processing of external entities [fedora-all]
bugzilla·2016-03-29·CVSS 7.5
CVE-2016-3674 [HIGH] CVE-2016-3674 jenkins-xstream: XStream: enabled processing of external entities [fedora-all]
CVE-2016-3674 jenkins-xstream: XStream: enabled processing of external entities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
arXiv
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
arxiv_fulltext·2021-08-18
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
Triet Huynh Minh Le1,
David Hin12,
Roland Croft12 and
M. Ali Babar12
1CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia
2Cyber Security Cooperative Research Centre, Australia
\triet.h.le, david.hin, roland.croft, ali.babar\@adelaide.edu.au
## Abstract
It is increasingly suggested to identify Software Vulnerabilities (SVs) in code commits to give early warnings about potential security risks. However, there is a lack of effort to assess vulnerability-contributing commits right after they are detected to provide timely information about the exploitability, impact and severity of SVs. Such information is important to plan and prioritize the mitiga
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/183208.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2822.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2823.htmlhttp://www.debian.org/security/2016/dsa-3575http://www.openwall.com/lists/oss-security/2016/03/25/8http://www.openwall.com/lists/oss-security/2016/03/28/1http://www.securityfocus.com/bid/85381http://www.securitytracker.com/id/1036419http://x-stream.github.io/changes.html#1.4.9https://github.com/x-stream/xstream/issues/25http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/183208.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2822.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2823.htmlhttp://www.debian.org/security/2016/dsa-3575http://www.openwall.com/lists/oss-security/2016/03/25/8http://www.openwall.com/lists/oss-security/2016/03/28/1http://www.securityfocus.com/bid/85381http://www.securitytracker.com/id/1036419http://x-stream.github.io/changes.html#1.4.9https://github.com/x-stream/xstream/issues/25
2016-05-17
Published