Severity
7.5HIGH
EPSS
2.9%
top 13.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateAug 22

Description

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDxstream/xstream< 1.4.9
Debianlibxstream-java< 1.4.9-1+3
Ubuntulibxstream-java< 1.4.7-1ubuntu0.1+esm2+1

Also affects: Debian Linux 8.0, Fedora 22, 23

🔴Vulnerability Details

5
OSV
libxstream-java vulnerabilities2024-08-22
OSV
XML External Entity Injection in XStream2020-06-30
GHSA
XML External Entity Injection in XStream2020-06-30
CVEList
CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Standa2016-05-17
OSV
CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Standa2016-05-17

📋Vendor Advisories

3
Ubuntu
XStream vulnerabilities2024-08-22
Red Hat
XStream: enabled processing of external entities2016-03-15
Debian
CVE-2016-3674: libxstream-java - Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) D...2016

💬Community

4
Bugzilla
CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]2016-05-13
Bugzilla
CVE-2016-3674 XStream: enabled processing of external entities [fedora-all]2016-03-29
Bugzilla
CVE-2016-3674 XStream: enabled processing of external entities2016-03-29
Bugzilla
CVE-2016-3674 jenkins-xstream: XStream: enabled processing of external entities [fedora-all]2016-03-29
CVE-2016-3674 (HIGH CVSS 7.5) | Multiple XML external entity (XXE) | cvebase.io