XStream (x-stream.github.io) is a Java library to marshal Java objects into XML and back. For this purpose it supports a lot of different XML parsers. Some of those can also process external entities which was enabled by default. An attacker could therefore provide manipulated XML as input to access data on the file system, see https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing
Created jenkins-xstream tracking bugs for this issue: Affects: fedora-all [bug 1321792]
Created xstream tracking bugs for this issue: Affects: fedora-all [bug 1321791]
External References: https://github.com/x-stream/xstream/issues/25
xstream-1.4.9-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
xstream-1.4.9-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
xstream-1.4.9-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: Red Hat JBoss BRMS 6.4.0 Via RHSA-2016:2823 https://rhn.redhat.com/errata/RHSA-2016-2823.html
This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.4.0 Via RHSA-2016:2822 https://rhn.redhat.com/errata/RHSA-2016-2822.html