logo

Database

Lack of data validation In libxstream-java

Description

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-29505.yaml2. https://github.com/MyBlackManba/CVE-2021-295053. https://github.com/x-stream/xstream/security/advisories/GHSA-7chv-rrw6-w6fc4. https://github.com/x-stream/xstream/commit/24fac82191292c6ae25f94508d28b9823f83624f5. https://github.com/x-stream/xstream/commit/f0c4a8d861b68ffc3119cfbbbd632deee624e2276. https://x-stream.github.io/CVE-2021-29505.html7. https://www.oracle.com/security-alerts/cpuoct2021.html8. https://www.oracle.com/security-alerts/cpujul2022.html9. https://www.oracle.com/security-alerts/cpujan2022.html10. https://www.oracle.com/security-alerts/cpuapr2022.html11. https://www.debian.org/security/2021/dsa-500412. https://security.netapp.com/advisory/ntap-20210708-000713. https://lists.fedoraproject.org/archives/list/[email protected]/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB14. https://lists.fedoraproject.org/archives/list/[email protected]/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU715. https://lists.fedoraproject.org/archives/list/[email protected]/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP16. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB17. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU718. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP19. https://lists.apache.org/thread.html/r8ee51debf7fd184b6a6b020dc31df25118b0aa612885f12fbe77f04f@%3Cdev.jmeter.apache.org%3E20. https://lists.apache.org/thread.html/r8ee51debf7fd184b6a6b020dc31df25118b0aa612885f12fbe77f04f%40%3Cdev.jmeter.apache.org%3E