XStream before 1.4.15 is susceptible to server-side request forgery. An attacker can request data from internal resources that are not publicly available by manipulating the processed input stream, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
id: CVE-2020-26258
info:
name: XStream <1.4.15 - Server-Side Request Forgery
author: pwnhxl
s
...