com.thoughtworks.xstream:xstream vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the com.thoughtworks.xstream:xstream package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Deserialization of Untrusted Data

[,1.4.21)
  • M
Denial of Service (DoS)

[,1.4.20)
  • M
Denial of Service (DoS)

[0,1.4.20)
  • H
Denial of Service (DoS)

[,1.4.19)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Remote Code Execution (RCE)

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • M
Denial of Service (DoS)

[,1.4.18)
  • H
Deserialization of Untrusted Data

[,1.4.18)
  • H
Server-Side Request Forgery (SSRF)

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • H
Arbitrary Code Execution

[,1.4.18)
  • M
Deserialization of Untrusted Data

[,1.4.17)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • H
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Deserialization of Untrusted Data

[,1.4.16)
  • M
Server-Side Request Forgery (SSRF)

[,1.4.15)
  • M
Arbitrary File Deletion

[,1.4.15)
  • H
Deserialization of Untrusted Data

[,1.4.14)
  • C
Deserialization of Untrusted Data

[1.4.10,1.4.11)
  • H
Denial of Service (DoS)

[,1.4.10)
  • M
Insecure XML deserialization

[,1.4.7) [1.4.10,1.4.11)
  • H
XML External Entity (XXE) Injection

[0.3,1.4.9)

Package versions

1 - 45 of 45 Results
version published direct vulnerabilities
1.4.20 23 Dec, 2022
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
1.4.19 29 Jan, 2022
  • 0
    C
  • 1
    H
  • 2
    M
  • 0
    L
1.4.18 22 Aug, 2021
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
1.4.17 14 May, 2021
  • 0
    C
  • 15
    H
  • 3
    M
  • 0
    L
1.4.16 12 Mar, 2021
  • 0
    C
  • 15
    H
  • 4
    M
  • 0
    L
1.4.15 12 Dec, 2020
  • 0
    C
  • 16
    H
  • 14
    M
  • 0
    L
1.4.14-jdk7 15 Nov, 2020
  • 0
    C
  • 16
    H
  • 16
    M
  • 0
    L
1.4.14-java7 24 Nov, 2020
  • 0
    C
  • 16
    H
  • 16
    M
  • 0
    L
1.4.14 15 Nov, 2020
  • 0
    C
  • 16
    H
  • 16
    M
  • 0
    L
1.4.13-java7 6 Sep, 2020
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.13 6 Sep, 2020
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.12-java7 12 Apr, 2020
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.12 12 Apr, 2020
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.11.1 26 Oct, 2018
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.11-java7 22 Oct, 2018
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.11 22 Oct, 2018
  • 0
    C
  • 17
    H
  • 16
    M
  • 0
    L
1.4.10-java7 23 May, 2017
  • 1
    C
  • 17
    H
  • 17
    M
  • 0
    L
1.4.10 23 May, 2017
  • 1
    C
  • 17
    H
  • 17
    M
  • 0
    L
1.4.9 15 Mar, 2016
  • 0
    C
  • 18
    H
  • 16
    M
  • 0
    L
1.4.8 18 Feb, 2015
  • 0
    C
  • 19
    H
  • 16
    M
  • 0
    L
1.4.7 8 Feb, 2014
  • 0
    C
  • 19
    H
  • 16
    M
  • 0
    L
1.4.6 12 Dec, 2013
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.4.5 28 Sep, 2013
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.4.4 19 Jan, 2013
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.4.3 17 Jul, 2012
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.4.2 3 Nov, 2011
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.4.1 11 Aug, 2011
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.4 6 Aug, 2011
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.3.1 6 Dec, 2008
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.3 26 Feb, 2008
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.2.2 24 May, 2007
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.2.1 11 Nov, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.2 18 Aug, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.1.3 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.1.2 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.1.1 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.1 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.0.2 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.0.1 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
1.0 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
0.6 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
0.5 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
0.3 19 Sep, 2006
  • 0
    C
  • 19
    H
  • 17
    M
  • 0
    L
0.2 19 Sep, 2006
  • 0
    C
  • 18
    H
  • 17
    M
  • 0
    L
0.1 19 Sep, 2006
  • 0
    C
  • 18
    H
  • 17
    M
  • 0
    L