Loading
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Use CWE-94, Xstream vendor hub and Xstream product page to widen CVE-2019-10173 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-39152, CVE-2021-39150 and CVE-2021-39154 for nearby disclosures in the same product family.