V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2021-21341
DEB
MediumConfirmedExploit available

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may al…

CVSS
5.9
Medium
EPSS
0.30
p96
Published
2021-01-01
Updated
2021-01-01
Description

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

Tags · CWE
Pre-auth
CWE-400
CWE-502
CAPEC-147
CAPEC-227
CAPEC-492
CAPEC-586
Affected products
Activemq < 5.15.14ActivemqJmeter < 5.5
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.302 · p96
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
CVE-2021-21341
github-poc · https://github.com/s-index/CVE-2021-21341
Enterprise
Affected software
ProductVendorStatus
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
activemq*Tracked
banking_enterprise_default_management*Tracked
banking_platform*Tracked
business_activity_monitoring*Tracked
communications_billing_and_revenue_management_elastic_charging_engine*Tracked
Source databases
DEB
CVE
UBU