Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2021-29505
Severity
8.8HIGH
EPSS
90.8%
top 0.38%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 28
Latest updateJul 15
Description
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9
Affected Packages17 packages
Also affects: Debian Linux 10.0, 11.0, 9.0, Fedora 33, 34, 35
Patches
🔴Vulnerability Details
4OSV
▶
💥Exploits & PoCs
1Nuclei▶
XStream <1.4.17 - Remote Code Execution
📋Vendor Advisories
5Oracle▶
Oracle Oracle Communications Applications Risk Matrix: Rulesets (XStream) — CVE-2021-29505↗2022-01-15
Oracle▶
Oracle Oracle Enterprise Manager Risk Matrix: Guest Management (XStream) — CVE-2021-29505↗2021-10-15
Red Hat
▶
Debian▶
CVE-2021-29505: libxstream-java - XStream is software for serializing Java objects to XML and back again. A vulner...↗2021