XML External Entity Injection in XStream
High severity
GitHub Reviewed
Published
Jun 30, 2020
to the GitHub Advisory Database
•
Updated May 23, 2025
Description
Published by the National Vulnerability Database
May 17, 2016
Reviewed
Jun 30, 2020
Published to the GitHub Advisory Database
Jun 30, 2020
Last updated
May 23, 2025
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
References