[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-39144Date: (C)2021-08-24   (M)2023-12-22


XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.5CVSS Score : 6.0
Exploit Score: 1.8Exploit Score: 6.8
Impact Score: 6.0Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
DSA-5004
FEDORA-2021-5e376c0ed9
FEDORA-2021-d894ca87dc
FEDORA-2021-fbad11014a
N/A
https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html
http://packetstormsecurity.com/files/169859/VMware-NSX-Manager-XStream-Unauthenticated-Remote-Code-Execution.html
https://github.com/x-stream/xstream/security/advisories/GHSA-j9h8-phrw-h4fh
https://security.netapp.com/advisory/ntap-20210923-0003/
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://x-stream.github.io/CVE-2021-39144.html

CPE    1
cpe:/o:debian:debian_linux:9.0
CWE    1
CWE-306
OVAL    8
oval:org.secpod.oval:def:120871
oval:org.secpod.oval:def:120874
oval:org.secpod.oval:def:708024
oval:org.secpod.oval:def:89392
...

© SecPod Technologies