CVE-2021-39147: XStream is vulnerable to an Arbitrary Code Execution attack
A flaw was found in xstream, a simple library used to serialize objects to XML and back again. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 0:1.3.1-16.el7_9 - Upgrade
Upgrade
debian/libxstream-javato a version that resolves this vulnerability.Fixed in 1.4.11.1-1+deb10u3Fixed in 1.4.11.1-1+deb10u4Fixed in 1.4.15-3+deb11u2Fixed in 1.4.20-1 - Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Upgrade
Upgrade
x-stream/xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Configuration
Set up XStream's security framework with a whitelist limited to the minimal required types (do not allow general-purpose deserialization).
XStream security framework whitelist (minimal required types) = enabled/limited
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-39147?
CVE-2021-39147 is a vulnerability in the XStream library that allows a remote attacker to load and execute arbitrary code by manipulating the input stream.
What is the severity of CVE-2021-39147?
The severity of CVE-2021-39147 is high, with a severity value of 8.5.
Which versions of XStream are affected by CVE-2021-39147?
Versions up to and exclusive of 1.4.18 of XStream are affected by CVE-2021-39147.
How can I fix CVE-2021-39147?
To fix CVE-2021-39147, it is recommended to update XStream to version 1.4.18 or apply the relevant patches provided by the vendor.
Where can I find more information about CVE-2021-39147?
You can find more information about CVE-2021-39147 in the official security advisories and bug reports provided by the XStream project, Red Hat, and other relevant sources.