Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java.
This issue affects tis: before v4.3.0.
This issue affects tis: before v4.3.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/datavane/tis/pull/443 |
|
History
Tue, 27 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before v4.3.0. | |
| Title | A XStream Security Vulnerability in XML Deserialization in datavane/tis | |
| Weaknesses | CWE-434 CWE-502 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GovTech CSG
Published:
Updated: 2026-01-27T08:51:58.830Z
Reserved: 2026-01-27T08:48:56.893Z
Link: CVE-2026-24815
No data.
Status : Awaiting Analysis
Published: 2026-01-27T09:15:51.967
Modified: 2026-01-27T14:59:34.073
Link: CVE-2026-24815
No data.
OpenCVE Enrichment
No data.