CVE advisoryCRITICAL
CVE-2013-7285
Xstream XML Processing Vulnerability Allows Command Execution.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
The XStream API, a Java library for processing XML and JSON, has a vulnerability where uninitialized security frameworks could allow remote attackers to execute arbitrary shell commands by manipulating input streams during data unmarshalling. This could affect system data and service behavior. Confirmation of XStream u