This issue affects tis: before v4.3.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/datavane/tis/pull/443 |
|
Tue, 27 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datavane
Datavane tis |
|
| Vendors & Products |
Datavane
Datavane tis |
Tue, 27 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before v4.3.0. | |
| Title | A XStream Security Vulnerability in XML Deserialization in datavane/tis | |
| Weaknesses | CWE-434 CWE-502 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GovTech CSG
Published:
Updated: 2026-01-27T20:41:20.316Z
Reserved: 2026-01-27T08:48:56.893Z
Link: CVE-2026-24815
Updated: 2026-01-27T20:41:16.316Z
Status : Deferred
Published: 2026-01-27T09:15:51.967
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-24815
No data.
OpenCVE Enrichment
Updated: 2026-04-18T02:30:15Z