← Back to CVE List

CVE-2013-7285

Published: 2019-05-15T17:29Z
Last Modified: 2025-04-01T13:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt