Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38676
HistoryDec 28, 2022 - 7:50 a.m.

Denial Of Service(DoS)

2022-12-2807:50:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
denial of service
xstream.java
stack overflow
input stream manipulation

0.01 Low

EPSS

Percentile

83.8%

xstream core is vulnerable to Denial Of Service(DoS). The vulnerability exists in the unmarshal function in XStream.java due to a stack overflow which allows an attacker to manipulate the processed input stream at unmarshalling time and replace or inject objects calculating a recursive hash set.