PromptRiskDBThreat intelligence atlas

CVE-2021-39144 - XStream XStream

AI Vulnerability Context

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no long...

Overview

A source-backed snapshot of this vulnerability.

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2021-39144
Vendor/project
XStream
Product
XStream
Vulnerability name
XStream Remote Code Execution Vulnerability
Date added
2023-03-10
Due date
2023-03-31
Known ransomware campaign use
Unknown
CVSS v3
8.5
CWE-502CWE-94

Exploit context

What the vulnerability is about.

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.