← Back to CVE List
Vulnerability Intelligence Report
A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling

CVE-2021-39150

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.

No Active Exploit Signals
CVSS Base Score
8.5
HIGH
Exploitability:1.8
Impact Score:6.1
EPSS Probability:3.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-502 ↗CWE-502: Deserialization of Untrusted Data
CWE-918 ↗CWE-918: Server-Side Request Forgery (SSRF)

Affected Products & Versions

Vendor Product Affected Versions
x-stream xstream < 1.4.18 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.465%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2021-08-16T00:00:00
Published2021-08-23T18:20:15
Last Updated2024-08-04T01:58:18

LINK COPIED TO CLIPBOARD