peter bassill · operator
$ cve CVE-2021-39144 JSON

CVE-2021-39144 KEV

8.5
HIGH · CVSS 3.1 · EPSS 98.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-03-31.

Description

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

Scoring

CVSS8.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS98.12% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2023-03-31
Public exploitnone known
Published2021-08-23
Last modified2026-06-17

CISA KEV

NameXStream Remote Code Execution Vulnerability
Added2023-03-10
Due2023-03-31
Vendor / productXStream / XStream
Ransomware usenone reported

Affected (15)

VendorProduct
debiandebian linux
fedoraprojectfedora
netappsnapmanager
oraclebusiness activity monitoring
oraclecommerce guided search
oraclecommunications billing and revenue management elastic charging engine
oraclecommunications cloud native core automated test suite
oraclecommunications cloud native core binding support function
oraclecommunications cloud native core policy
oraclecommunications unified inventory management
oracleretail xstore point of service
oracleutilities framework
oracleutilities testing accelerator
oraclewebcenter portal
xstreamxstream

References

→ the Explorer  ·  watch your stack  ·  NVD