Skip to content

XStream - remote code execution due to insecure XML deserialization #835

@thboileau

Description

@thboileau

As reported by David Jorm:

this issue: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7285
will affect the org.restlet.ext.xstream extension. It can be resolved by upgrading to XStream 1.4.7 and using the security framework documented here: http://xstream.codehaus.org/security.html
to only allow trusted types to be deserialized.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions