xstream icon indicating copy to clipboard operation
xstream copied to clipboard

What is the trigger condition of CVE-2022-40156 CVE-2022-40153 CVE-2022-40154 CVE-2022-40155, XStream. fromXML? Is the version affected only when XStream.fromXML is called?

Open BadTrasher opened this issue 3 years ago • 6 comments

BadTrasher avatar Sep 23 '22 06:09 BadTrasher

will there be a security update?

https://avd.aquasec.com/nvd/2022/cve-2022-40153/

3XC1T3D avatar Sep 29 '22 11:09 3XC1T3D

Related to the current version, and not exactly sure where to post the comment. But wondering when aa new version may be available that addresses the 9 vulns currently affecting version 1.4.19 https://mvnrepository.com/artifact/com.thoughtworks.xstream/xstream/1.4.19

tim-jacobsen-wgu avatar Sep 29 '22 18:09 tim-jacobsen-wgu

Any News about that CVE's and their fixes?

Best regards

3XC1T3D avatar Oct 09 '22 19:10 3XC1T3D

Also looking for an update on the Open CVEs against Xstream CVE-2022-40156 CVE-2022-40155 CVE-2022-40154 CVE-2022-40153 CVE-2022-40152 CVE-2022-40151 #304 appears to also mention these CVEs. Will that ticket cover all CVE's above?

Derv0 avatar Oct 10 '22 14:10 Derv0

Jenkins uses this xstream & the grace period is also over (expired 6 days ago) for the CVE's (CVE-2022-40152, CVE-2022-40151) When we can expect the fix ?

smarlaku820 avatar Oct 12 '22 09:10 smarlaku820

I've come here after getting CVE warnings too. Based on https://github.com/x-stream/xstream/issues/262, I suspect most users should consider switching to alternative APIs/libs - eg XMLInputFactory (StAX parsing), jackson-dataformat-xml, JAXB, etc.

Thanks @joehni for maintaining this great library. Those OSS Fuzz guys are causing real chaos in the OSS community. They should try much harder to engage with lib maintainers before raising the CVEs.

pjfanning avatar Oct 13 '22 09:10 pjfanning

I agree, XStream is an amazing library! @pjfanning , maybe i misunderstood, but is there news of the XStream project closing that you suggest switching to alternatives and giving (well deserved) thanks to @joehni ?

act-amirsky avatar Oct 18 '22 10:10 act-amirsky

As most of you may have noticed, XStream cannot do anything about CVEs 2022-40152 to 2022-40156. Apart from that this ticket simply duplifies #304.

joehni avatar Nov 14 '22 23:11 joehni