Security Advisory

CVE-2018-18240

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-10-11 07:00:00
Last updated 2024-09-16 19:50:53
Assigner mitre
State PUBLISHED

Description

Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStreams available protection mechanisms to restrict unmarshalling.