Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What is the trigger condition of CVE-2022-40156 CVE-2022-40153 CVE-2022-40154 CVE-2022-40155, XStream. fromXML? Is the version affected only when XStream.fromXML is called? #311

Closed
BadTrasher opened this issue Sep 23, 2022 · 8 comments
Assignees

Comments

@BadTrasher
Copy link

No description provided.

@3XC1T3D
Copy link

3XC1T3D commented Sep 29, 2022

will there be a security update?

https://avd.aquasec.com/nvd/2022/cve-2022-40153/

@tim-jacobsen-wgu
Copy link

Related to the current version, and not exactly sure where to post the comment. But wondering when aa new version may be available that addresses the 9 vulns currently affecting version 1.4.19
https://mvnrepository.com/artifact/com.thoughtworks.xstream/xstream/1.4.19

@3XC1T3D
Copy link

3XC1T3D commented Oct 9, 2022

Any News about that CVE's and their fixes?

Best regards

@Derv0
Copy link

Derv0 commented Oct 10, 2022

Also looking for an update on the Open CVEs against Xstream
CVE-2022-40156
CVE-2022-40155
CVE-2022-40154
CVE-2022-40153
CVE-2022-40152
CVE-2022-40151
#304 appears to also mention these CVEs. Will that ticket cover all CVE's above?

@smarlaku820
Copy link

Jenkins uses this xstream & the grace period is also over (expired 6 days ago) for the CVE's (CVE-2022-40152, CVE-2022-40151)
When we can expect the fix ?

@pjfanning
Copy link

pjfanning commented Oct 13, 2022

I've come here after getting CVE warnings too. Based on #262, I suspect most users should consider switching to alternative APIs/libs - eg XMLInputFactory (StAX parsing), jackson-dataformat-xml, JAXB, etc.

Thanks @joehni for maintaining this great library. Those OSS Fuzz guys are causing real chaos in the OSS community. They should try much harder to engage with lib maintainers before raising the CVEs.

@act-amirsky
Copy link

I agree, XStream is an amazing library! @pjfanning , maybe i misunderstood, but is there news of the XStream project closing that you suggest switching to alternatives and giving (well deserved) thanks to @joehni ?

@joehni joehni self-assigned this Nov 14, 2022
@joehni
Copy link
Member

joehni commented Nov 14, 2022

As most of you may have noticed, XStream cannot do anything about CVEs 2022-40152 to 2022-40156. Apart from that this ticket simply duplifies #304.

@joehni joehni closed this as completed Nov 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

8 participants