CVE-2021-29505: XStream is vulnerable to a Remote Command Execution attack
Impact The vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types.
Patches If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.17.
Workarounds See workarounds for the different versions covering all CVEs.
References See full information about the nature of the vulnerability and the steps to reproduce it in XStream's documentation for CVE-2021-29505.
Credits
V3geB1rd, white hat hacker from Tencent Security Response Center found and reported the issue to XStream and provided the required information to reproduce it.
For more information If you have any questions or comments about this advisory: Open an issue in XStream Email us at XStream Google Group
Other sources
A flaw was found in XStream. By manipulating the processed input stream, a remote attacker may be able to obtain sufficient rights to execute commands. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
The vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types.
Reference: https://github.com/x-stream/xstream/security/advisories/GHSA-7chv-rrw6-w6fc
— Red Hat
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-29505?
CVE-2021-29505 is a vulnerability in XStream, a software for serializing Java objects to XML, which allows a remote attacker to execute commands by manipulating the input stream.
What is the severity of CVE-2021-29505?
The severity of CVE-2021-29505 is high with a CVSS score of 8.8.
Which versions of XStream are affected by CVE-2021-29505?
Versions of XStream prior to 1.4.17 are affected by CVE-2021-29505.
How can I fix CVE-2021-29505?
To fix CVE-2021-29505, it is recommended to update XStream to version 1.4.17 or later.
Where can I find more information about CVE-2021-29505?
You can find more information about CVE-2021-29505 on the GitHub security advisory and the Red Hat Bugzilla page.