← Back

CVE-2021-21342

nvd nist
Published: Mar 23, 2021Modified: May 23, 2025

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in a server-side forgery request. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

Affected (38)

Show all products
1 product
Oncommand Insight
2 products
Activemq
Jmeter
1 product
Xstream
1 product
Debian Linux
1 product
Fedora
9 products
Banking Platform
Business Activity Monitoring
Communications Policy Management
Retail Xstore Point Of Service
Webcenter Portal
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 5.15.14
Version 5.16.0
Version 5.16.1
Before 5.5
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.16
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Version 35
Configuration F
26 vulnerable

References (30)

Source: security-advisories@github.com
Release NotesThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Issue TrackingMailing ListThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Not ApplicablePatchVendor Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
ExploitThird Party Advisory
Source: security-advisories@github.com
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicablePatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.