Description
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages5 packages
Also affects: Debian Linux 8.0, 9.0
🔴Vulnerability Details
4GHSADenial of service in XStream↗2020-06-30 ▶ OSVDenial of service in XStream↗2020-06-30 ▶ CVEListCVE-2017-7957: XStream through 1↗2017-04-29 ▶ OSVCVE-2017-7957: XStream through 1↗2017-04-29 ▶ 📋Vendor Advisories
3AtlassianCVE-2017-7957: DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server↗2024-01-16 ▶ Red HatXStream: DoS when unmarshalling void type↗2017-04-03 ▶ DebianCVE-2017-7957: libxstream-java - XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandl...↗2017 ▶ 💬Community
5BugzillaCVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]↗2018-07-05 ▶ BugzillaCVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]↗2017-08-14 ▶ BugzillaCVE-2017-7957 XStream: DoS when unmarshalling void type↗2017-04-12 ▶ BugzillaCVE-2017-7957 jenkins-xstream: XStream: DoS when unmarshalling void type [fedora-all]↗2017-04-12 ▶ BugzillaCVE-2017-7957 XStream: DoS when unmarshalling void type [fedora-all]↗2017-04-12 ▶