CVE-2017-7957

Severity
7.5HIGH
EPSS
2.6%
top 14.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29
Latest updateJan 16

Description

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

4
GHSA
Denial of service in XStream2020-06-30
OSV
Denial of service in XStream2020-06-30
CVEList
CVE-2017-7957: XStream through 12017-04-29
OSV
CVE-2017-7957: XStream through 12017-04-29

📋Vendor Advisories

3
Atlassian
CVE-2017-7957: DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server2024-01-16
Red Hat
XStream: DoS when unmarshalling void type2017-04-03
Debian
CVE-2017-7957: libxstream-java - XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandl...2017

💬Community

5
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]2018-07-05
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]2017-08-14
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type2017-04-12
Bugzilla
CVE-2017-7957 jenkins-xstream: XStream: DoS when unmarshalling void type [fedora-all]2017-04-12
Bugzilla
CVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]2017-04-12
CVE-2017-7957 (HIGH CVSS 7.5) | XStream through 1.4.9 | cvebase.io